Information Disclosure in MongoDB SQL Schema Builder CLI
CVE-2026-19502

6.8MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19502?

The MongoDB SQL Schema Builder CLI has a vulnerability where it inadvertently logs sensitive authentication settings to standard output and log files. This information may be accessed by local users with read permissions to the terminal or the log directory. If logging is enabled, unredacted connection details can expose sensitive data, allowing unauthorized access to authentication information stored in plain text. Proper measures should be taken to protect log files and terminal outputs from unauthorized access to mitigate this risk.

Affected Version(s)

Schema Builder CLI 1.0.0 < 1.2.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.