CVE-2026-19502: MongoDB SQL Schema Builder CLI
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values.
Affected products
- MongoDB SQL Schema Builder CLI: from 1.0.1, before 1.2.1 (fixed in 1.2.1)
Published 2026-08-12. Last modified 2026-09-29.