← back
CVE-2026-75573mediumCWE-532

MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are Supplied

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.1epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
MongoDB · BI Connector