๐Ÿ” CVE Alert

CVE-2026-75573

MEDIUM 4.4

MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are Supplied

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

CWE CWE-532
Vendor mongodb
Product bi connector
Ecosystems
Industries
Technology
Published Aug 27, 2026
Last Updated Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb bi connector

Be the first to know when new medium vulnerabilities affecting mongodb bi connector are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

MongoDB / BI Connector
2.12.0 < 2.14.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mongodb.com: https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30