CVE-2026-75573: MongoDB BI Connector
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.
Affected products
- MongoDB BI Connector: from 2.12.0, before 2.14.30 (fixed in 2.14.30)
Published 2026-08-27. Last modified 2026-09-23.