TLS Private-Key Password Exposure in MongoDB Connector for BI
CVE-2026-75573

4.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
27 August 2026

What is CVE-2026-75573?

In the MongoDB Connector for BI, a security flaw exists where the TLS private-key password can be inadvertently written to the standard error output. This can occur when the password is supplied via both the connection URI and the command-line option. If a local user can access the captured command output alongside the encrypted key file, the exposed password can potentially grant unauthorized access to the associated TLS client key, posing a significant risk to data security and integrity.

Affected Version(s)

BI Connector 2.12.0 < 2.14.30

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.