AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18710

MEDIUM · CVSS 6.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The MongoDB driver component is vulnerable to exposing sensitive configuration information, including credentials for outbound network connectivity, in cleartext within application logs during routine client initialization. This vulnerability can be exploited by anyone with access to the application's logs or log-aggregation storage, potentially compromising the confidentiality of the credentials. Organizations using MongoDB should prioritize addressing this issue to safeguard their network infrastructure from unauthorized access.

CVE
CVE-2026-18710
Severity
MEDIUM
CVSS
6.5
EPSS
0.11%
MongoDB

Original NVD Description

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A party able to read the affected application's logs or downstream log-aggregation storage could recover the credential and reuse it to authenticate to the associated network infrastructure. This issue affects confidentiality only.