{"id":"CVE-2026-19502","title":"MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk","summary":"MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-532"],"vendor":"mongodb","product":"sql_schema_builder_cli","affected":["sql_schema_builder_cli >= 1.0.1, < 1.2.1"],"patched":["sql_schema_builder_cli 1.2.1"],"published":"2026-08-12","updated":"2026-09-29","sourceUpdated":"2026-09-29T20:54:18.740","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19502","references":[{"url":"https://www.mongodb.com/docs/sql-interface/changelog","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.00113,"epssPercentile":0.01305,"ingestedAt":"2026-09-29T21:49:08.164Z","slug":"CVE-2026-19502","body":"## Overview\n\nMongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values.\n\n## Affected\n\n- `sql_schema_builder_cli >= 1.0.1, < 1.2.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sql_schema_builder_cli 1.2.1`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}