{"id":"CVE-2026-75573","title":"In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option","summary":"In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captur…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-532"],"vendor":"mongodb","product":"bi_connector","affected":["bi_connector >= 2.12.0, < 2.14.30"],"patched":["bi_connector 2.14.30"],"published":"2026-08-27","updated":"2026-09-23","sourceUpdated":"2026-09-23T16:26:42.130","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75573","references":[{"url":"https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.0009,"epssPercentile":0.00509,"ingestedAt":"2026-09-23T16:27:22.632Z","slug":"CVE-2026-75573","body":"## Overview\n\nIn MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.\n\n## Affected\n\n- `bi_connector >= 2.12.0, < 2.14.30`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bi_connector 2.14.30`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}