CVE-2026-8200

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted.  This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-121895 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

18 May 2026, 13:01

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-121895 - () https://jira.mongodb.org/browse/SERVER-121895 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
First Time Mongodb mongodb
Mongodb

13 May 2026, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 04:17

Updated : 2026-05-18 13:01


NVD link : CVE-2026-8200

Mitre link : CVE-2026-8200

CVE.ORG link : CVE-2026-8200


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-532

Insertion of Sensitive Information into Log File