CVE-2026-75573
MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are Supplied
CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.
| CWE | CWE-532 |
| Vendor | mongodb |
| Product | bi connector |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 27, 2026 |
| Last Updated | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for mongodb bi connector
Be the first to know when new medium vulnerabilities affecting mongodb bi connector are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
MongoDB / BI Connector
2.12.0 < 2.14.30