CVE-2026-75573EPSS p0.7%

CVE-2026-75573CVE-2026-75573

mongodb / bi_connector

Description

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

Scoring

CVSS 4.4 ()
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS0.10% probability of exploitation · percentile 0.7% · 2026-10-04T12:00:21Z
Last modified2026-09-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.