UBUNTU-CVE-2026-18710

Source
https://ubuntu.com/security/CVE-2026-18710
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-18710
Upstream
  • CVE-2026-18710
Published
2026-08-13T00:00:00Z
Modified
2026-08-13T19:30:08.838311845Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A party able to read the affected application's logs or downstream log-aggregation storage could recover the credential and reuse it to authenticate to the associated network infrastructure. This issue affects confidentiality only.

References

Affected packages

Ubuntu:16.04:LTS
mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/ubuntu/mongo-java-driver?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.12.4-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.12.4-1",
            "binary_name": "libmongodb-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json"
Ubuntu:18.04:LTS
mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/ubuntu/mongo-java-driver?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.3.0-1
3.6.2-1
3.6.3-2~18.04

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.3-2~18.04",
            "binary_name": "libmongodb-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json"
Ubuntu:20.04:LTS
mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/ubuntu/mongo-java-driver?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.3-2",
            "binary_name": "libmongodb-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json"
Ubuntu:22.04:LTS
mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/ubuntu/mongo-java-driver?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.3-2",
            "binary_name": "libmongodb-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json"
Ubuntu:24.04:LTS
mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/ubuntu/mongo-java-driver?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.3-2",
            "binary_name": "libmongodb-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json"
Ubuntu:26.04:LTS
mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/ubuntu/mongo-java-driver?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2
3.6.3-2build1
3.6.3-2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.3-2.1",
            "binary_name": "libmongodb-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18710.json"