Junglewise Threat Intelligence

CVE-2026-81530: MongoDB C# Driver credential exposure in diagnostic output

CVE-2026-81530 · Severity: medium · CVSS 5.6 · Published 2026-08-27

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C# Driver was logging sensitive key-management credentials in plaintext within diagnostic strings and process logs. An attacker with access to application logs, debug output, or memory dumps could recover these credentials and use them to decrypt protected database fields. The driver has been patched to redact these secrets, similar to how TLS credentials were already masked.

Technical details

A weakness in the AutoEncryptionOptions.ToString() method of the MongoDB C# Driver caused client-side encryption key-management credentials to be serialized in plaintext within the MongoClientSettings.ToString() output. The vulnerable component failed to redact KMS provider credentials and local master keys, exposing them wherever these diagnostic strings were logged or displayed. An attacker with access to application logs, error output, or process memory dumps could extract the plaintext credentials and use them to decrypt client-side encrypted database fields. The fix applies the same redaction pattern already used for TLS options by masking kmsProviders values with <hidden>. Patch: version 3.11.1 or later.

Affected products

  • MongoDB C# Driver before 3.11.1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-25: patched: Version 3.11.1 released

References

Related threats