Impact
The MongoDB C++ Driver discards content after an embedded NUL byte in field and collection names supplied to the driver. This truncation creates a source‑output confusion vulnerability where the driver and the calling application interpret the same name differently. As a result, an authenticated user with the ability to influence a name can cause the application to read from an unintended field or rename an unintended collection, exposing confidential data or altering database objects. The flaw relies solely on the application’s existing database credentials and does not require higher privileges.
Affected Systems
MongoDB C++ Driver is the affected product. No specific affected versions are listed, so the issue applies to all releases that contain the described truncation behavior.
Risk and Exploitability
The CVSS score of 6.0 indicates medium severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no documented public exploitation at the time of the advisory. The likely attack vector is an authenticated actor who can specify collection or field names; by including an embedded NUL byte the driver truncates the name while the application uses the full string, leading to unintended data access or object renaming. The risk is bounded to accounts that possess write or administrative rights on the database.
OpenCVE Enrichment