MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.
{
"cna_assigner": "mongodb",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9735.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.3"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-532"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1759.0,
"function_hash": "33576969391667528712105414855855095210"
},
"id": "CVE-2026-9735-3818d52e",
"signature_type": "Function",
"source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
"target": {
"function": "_speculateSaslStart",
"file": "src/mongo/client/authenticate.cpp"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"105051277585384029869713401387324710299",
"135010353328424632509818700676883262741",
"230022231509017531526336883388413859957",
"21785236440502061071534570285577718704",
"314611412092879437439966455802374359968",
"4328176094298166889601989525363512001",
"89833129311893956686513176585485383462",
"67104821923433815313850425352519867386",
"66993897057338546953195861906592522514",
"41622748248584985132494531963597557744",
"242973420897860388216828233337695113596",
"336731002354755517834207641772257008949",
"64002474223761432976487321914411588332",
"261309617626622354563994167105861925016",
"229808833034910568928737793619657257065",
"327973055814987959560058864332639589393",
"331230983148226970461307129171652554653",
"194280706403459704585085037893015299868",
"132169427929260727166827845414640998831",
"263821533391834434161668531794875587617",
"231008637408865177850436966867033654335",
"131209670928832011957508828184726650364",
"64002474223761432976487321914411588332",
"261309617626622354563994167105861925016",
"152599178162463674149335674778053474470",
"82317842280543420915626715536098646954",
"89485288152782603664608867313022701634",
"201049280170827963568948467383659578170",
"186915239712986481660363218458077044420",
"81595865256585900407563580384512090789",
"89485288152782603664608867313022701634",
"201049280170827963568948467383659578170"
]
},
"id": "CVE-2026-9735-80a3d3f5",
"signature_type": "Line",
"source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
"target": {
"file": "src/mongo/client/authenticate.cpp"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 2313.0,
"function_hash": "20399944836295365806244165546970965254"
},
"id": "CVE-2026-9735-99e1e8a5",
"signature_type": "Function",
"source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
"target": {
"function": "saslClientAuthenticateImpl",
"file": "src/mongo/client/sasl_client_authenticate_impl.cpp"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"119297248915920219031821473937269301824",
"192950127050229143070957758609674490481",
"299256134244687864194021167969650322418",
"78705388978130039955877200458257143577",
"321869386180767067962050016171660673429",
"92304406178298145235033043329826640960",
"203486625542267065639036914103785025824",
"101091632339192440179784421579332741865",
"121174813050634776452676460079189488323",
"128019987876497809896042531600850302807",
"254894470578114612803585286215406515998",
"214382625466148222914899976163699517733",
"190404496706438243159513143102836777584",
"56154081985503966229462899327055184543",
"208419707775319461290978685733013608031",
"112980909939898786886727276248725730797",
"125593633845177966189813606560474867521",
"171922900114146216740577553907126530807",
"101091632339192440179784421579332741865",
"264963333426305115134532843740947636372",
"89987837705424899310632089922787348176",
"57891838713164422666568581445619931080",
"60290105400638828282268502673375231284",
"142183950137575110969330755820960546057",
"56154081985503966229462899327055184543",
"208419707775319461290978685733013608031"
]
},
"id": "CVE-2026-9735-bae78291",
"signature_type": "Line",
"source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
"target": {
"file": "src/mongo/client/sasl_client_authenticate_impl.cpp"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1778.0,
"function_hash": "45101164990253539481215998889390091905"
},
"id": "CVE-2026-9735-e4b18909",
"signature_type": "Function",
"source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
"target": {
"function": "authX509",
"file": "src/mongo/client/authenticate.cpp"
}
}
]
"2026-07-25T08:12:10Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9735.json"