← back
CVE-2026-9735mediumCWE-532

Keyfile contents are in MongoDB Server logs

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
MongoDB · MongoDB Server