CVE-2026-8200
Severity CVSS v4.0:
MEDIUM
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
13/05/2026
Last modified:
13/05/2026
Description
When schema validation is enabled on a collection and an update or insert would violate the collection&#39;s schema, the local server log message generated may not have all user data redacted. <br />
<br />
<br />
This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
2.70
Severity 3.x
LOW



