Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog |
|
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb schema Builder Cli |
|
| Vendors & Products |
Mongodb
Mongodb schema Builder Cli |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values. | |
| Title | Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-13T12:46:38.135Z
Reserved: 2026-08-10T18:59:30.556Z
Link: CVE-2026-19502
Updated: 2026-08-13T12:46:29.102Z
Status : Received
Published: 2026-08-12T21:17:38.240
Modified: 2026-08-13T13:17:48.870
Link: CVE-2026-19502
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:47:59Z