Vulnerability Description
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-75573?
CVE-2026-75573 is a vulnerability with a CVSS score of 4.4 (MEDIUM). In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A...
How severe is CVE-2026-75573?
CVE-2026-75573 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-75573?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.