A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret fields are. A party able to read the application's logs, diagnostic output, or a process memory dump may thereby recover the plaintext credentials and use them to decrypt protected field data.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb c# Driver |
|
| Vendors & Products |
Mongodb
Mongodb c# Driver |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret fields are. A party able to read the application's logs, diagnostic output, or a process memory dump may thereby recover the plaintext credentials and use them to decrypt protected field data. | |
| Title | KMS master key exposure via unredacted credential serialization in driver settings string | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-27T22:34:52.470Z
Reserved: 2026-08-26T22:14:35.993Z
Link: CVE-2026-81530
No data.
Status : Received
Published: 2026-08-27T20:18:51.620
Modified: 2026-08-28T00:18:21.483
Link: CVE-2026-81530
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z