Description
A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials are properly redacted in server log output, but the diagnostic interface omits equivalent redaction. Successful exploitation requires a valid authenticated session with monitoring-level permissions and results in exposure of cleartext credentials that could enable impersonation of other users, including privileged accounts.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exposure
Action: Update & Restrict
AI Analysis

Impact

MongoDB Server's diagnostic reporting interface fails to redact credentials that are otherwise masked in log output. When accessed by an authenticated user with monitoring privileges, cleartext credentials from concurrent administrative operations can be viewed. Exposure of these credentials could allow an attacker to impersonate other users, including those with elevated or privileged access. The flaw is represented by CWE-522 and results in a confidentiality compromise for user credentials.

Affected Systems

The vulnerability affects MongoDB Server. No specific version numbers are listed in the CNA data; any instance of MongoDB Server that implements the diagnostic reporting interface is potentially impacted. Users running MongoDB Server should verify if they have enabled monitoring privileges and the diagnostic reporting feature.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium to high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires a valid authenticated session with monitoring-level permissions; Based on the description, it is inferred that no publicly disclosed exploit path is currently known. Because monitoring privileges are typically limited, the potential impact depends heavily on the privileges assigned to those users. Organizations should assess whether monitoring roles are assigned to trusted accounts and consider patching.

Generated by OpenCVE AI on September 8, 2026 at 18:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify and install the latest MongoDB Server release that includes a fix for the diagnostic reporting interface bug.
  • Restrict monitoring privileges to only trusted accounts and consider removing monitoring access for users who do not require it.
  • Disable the diagnostic reporting interface or restrict access to it if an update is not immediately available.

Generated by OpenCVE AI on September 8, 2026 at 18:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*
cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*
cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials are properly redacted in server log output, but the diagnostic interface omits equivalent redaction. Successful exploitation requires a valid authenticated session with monitoring-level permissions and results in exposure of cleartext credentials that could enable impersonation of other users, including privileged accounts.
Title Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:52:34.958Z

Reserved: 2026-08-27T22:53:28.622Z

Link: CVE-2026-82070

cve-icon Vulnrichment

Updated: 2026-09-08T17:52:32.349Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:36.010

Modified: 2026-09-16T20:38:56.103

Link: CVE-2026-82070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:45:05Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials