TLS Private-Key Password Exposure in MongoDB Connector for BI
CVE-2026-75573
4.1MEDIUM
What is CVE-2026-75573?
In the MongoDB Connector for BI, a security flaw exists where the TLS private-key password can be inadvertently written to the standard error output. This can occur when the password is supplied via both the connection URI and the command-line option. If a local user can access the captured command output alongside the encrypted key file, the exposed password can potentially grant unauthorized access to the associated TLS client key, posing a significant risk to data security and integrity.
Affected Version(s)
BI Connector 2.12.0 < 2.14.30