---
id: CVE-2026-19502
title: >-
  MongoDB SQL Schema Builder CLI records its startup configuration to standard
  output and, when file logging is enabled, to a log file on disk
summary: >-
  MongoDB SQL Schema Builder CLI records its startup configuration to standard
  output and, when file logging is enabled, to a log file on disk. Certain
  connection settings were written without redaction, so authentication material
  supplied…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
vendor: mongodb
product: sql_schema_builder_cli
affected:
  - 'sql_schema_builder_cli >= 1.0.1, < 1.2.1'
patched:
  - sql_schema_builder_cli 1.2.1
published: '2026-08-12'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:54:18.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19502'
references:
  - url: 'https://www.mongodb.com/docs/sql-interface/changelog'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00113
epssPercentile: 0.01305
ingestedAt: '2026-09-29T21:49:08.164Z'
---

## Overview

MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user with read access to the terminal session or the log directory, or anyone with access to a location where those logs are subsequently collected, could obtain those values.

## Affected

- `sql_schema_builder_cli >= 1.0.1, < 1.2.1`

## Remediation

Upgrade past the affected range:

- `sql_schema_builder_cli 1.2.1`
