---
id: CVE-2026-75573
title: >-
  In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to
  standard error when the password is supplied through both the connection URI
  and the corresponding command-line option
summary: >-
  In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to
  standard error when the password is supplied through both the connection URI
  and the corresponding command-line option. A local user with access to the
  captur…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
vendor: mongodb
product: bi_connector
affected:
  - 'bi_connector >= 2.12.0, < 2.14.30'
patched:
  - bi_connector 2.14.30
published: '2026-08-27'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T16:26:42.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75573'
references:
  - url: >-
      https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00098
epssPercentile: 0.00707
ingestedAt: '2026-09-23T16:27:22.632Z'
---

## Overview

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

## Affected

- `bi_connector >= 2.12.0, < 2.14.30`

## Remediation

Upgrade past the affected range:

- `bi_connector 2.14.30`
