Junglewise Threat Intelligence

CVE-2026-9735: MongoDB Server sensitive information disclosure in SASL authentication logs

CVE-2026-9735 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server, a widely used database system, contains a flaw where sensitive login credentials may be recorded in plain text within system logs. This occurs when specific connection health monitoring features are enabled, potentially exposing passwords to any user or process with access to the server's log files. An attacker with local access to the server could use these stolen credentials to gain unauthorized access to the database and its stored data.

Technical details

A sensitive information disclosure vulnerability (CWE-532) exists in MongoDB Server during SASL authentication. When connection health metric logging is enabled, the server fails to redact authentication parameters, resulting in full credentials being written to the egress logs. An attacker with local access and low privileges (PR:L) could read these logs to obtain valid credentials. The issue is addressed in MongoDB version 8.3.3 by ensuring SASL parameters are removed from egress logging.

Affected products

  • MongoDB MongoDB Server Versions prior to 8.3.3

Timeline

  • 2026-05-13: other: Issue reported internally at MongoDB
  • 2026-06-09: patched: Fix version 8.3.3 released and issue resolved
  • 2026-06-09: disclosed: CVE-2026-9735 published

References