Information Disclosure in MongoDB SQL Schema Builder CLI
CVE-2026-19502
6.8MEDIUM
What is CVE-2026-19502?
The MongoDB SQL Schema Builder CLI has a vulnerability where it inadvertently logs sensitive authentication settings to standard output and log files. This information may be accessed by local users with read permissions to the terminal or the log directory. If logging is enabled, unredacted connection details can expose sensitive data, allowing unauthorized access to authentication information stored in plain text. Proper measures should be taken to protect log files and terminal outputs from unauthorized access to mitigate this risk.
Affected Version(s)
Schema Builder CLI 1.0.0 < 1.2.1