cvedb.io
CVE-2026-9735
MEDIUM · CVSS 5.5
EPSS exploitation probability: 0%
Published 2026-06-09T23:17:03.287 · Last modified 2026-06-17T11:05:36.210

Summary

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

Affected products

mongodb — mongodb

Does this affect you?

Add your gear to cvedb and we'll alert you only when mongodb ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.