CVE-2026-9735: MongoDB
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.
Affected products
- MongoDB MongoDB: from 8.3.0, before 8.3.3 (fixed in 8.3.3)
Published 2026-06-09. Last modified 2026-07-23.