Security Issue in MongoDB Server's Reporting Interface Exposes Credentials
CVE-2026-82070

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82070?

A security issue exists in MongoDB Server's diagnostic reporting interface that permits an authenticated user with monitoring privileges to access sensitive credentials improperly secured during concurrent administrative operations. Although these credentials are typically redacted in server log outputs, the diagnostic interface fails to apply equivalent redaction measures. This vulnerability necessitates a valid authenticated session with monitoring-level permissions, leading to the potential exposure of cleartext credentials that may facilitate user impersonation, including access to privileged accounts.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.