PT-2026-48301 · Mongodb · Mongodb Server

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-9751

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2026-9751

Affected Products

Mongodb Server