Description
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog |
|
History
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values. | |
| Title | Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-12T20:14:33.274Z
Reserved: 2026-08-10T18:59:30.556Z
Link: CVE-2026-19502
No data.
Status : Received
Published: 2026-08-12T21:17:38.240
Modified: 2026-08-12T21:17:38.240
Link: CVE-2026-19502
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-532
Insertion of Sensitive Information into Log File