MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog |
|
History
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values. | |
| Title | Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-12T20:14:33.274Z
Reserved: 2026-08-10T18:59:30.556Z
Link: CVE-2026-19502
No data.
Status : Received
Published: 2026-08-12T21:17:38.240
Modified: 2026-08-12T21:17:38.240
Link: CVE-2026-19502
No data.
OpenCVE Enrichment
Updated: 2026-08-12T22:45:10Z
Weaknesses