Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-132835 |
|
Tue, 08 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb Server |
|
| Vendors & Products |
Mongodb
Mongodb mongodb Server |
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access unredacted search query text from other users' operations. An improper conditional check in the serialization logic causes the data redaction mechanism to be bypassed when processing search queries through the sharded cluster router. This results in sensitive query literals being stored and made accessible through the query statistics interface. | |
| Title | Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router | |
| Weaknesses | CWE-212 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-08T17:53:00.855Z
Reserved: 2026-08-27T22:53:17.721Z
Link: CVE-2026-82069
Updated: 2026-09-08T17:52:47.810Z
Status : Received
Published: 2026-09-08T17:18:35.877
Modified: 2026-09-08T18:21:02.193
Link: CVE-2026-82069
No data.
OpenCVE Enrichment
Updated: 2026-09-08T18:30:04Z