SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82070

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Server's diagnostic reporting interface is vulnerable, allowing authenticated users with monitoring privileges to access unredacted credentials from concurrent administrative operations. This exposure of cleartext credentials could lead to impersonation of other users, including those with elevated privileges. Organizations using MongoDB should prioritize this issue to mitigate potential unauthorized access and protect sensitive data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82070
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
MongoDB

Original NVD Description

A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials are properly redacted in server log output, but the diagnostic interface omits equivalent redaction. Successful exploitation requires a valid authenticated session with monitoring-level permissions and results in exposure of cleartext credentials that could enable impersonation of other users, including privileged accounts.

Related CVEs

Other vulnerabilities affecting the same vendor(s)