MEDIUMVulnerability

CVE-2026-75573

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

Properties

severity
MEDIUM
score
4.4
cve_id
CVE-2026-75573
signal_observed_at
2026-09-23T22:44:39+00:00
vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
published_at
2026-08-27T17:19:59.120
last_modified
2026-09-23T16:26:42.130

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information into Log File

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75573 — Ninja Signal Threat Intelligence | Ninja Signal