Impact
An authenticated user with read‑only privileges can issue a specially crafted aggregation command that triggers an internal engine selection inconsistency in MongoDB Server. The inconsistency leads to an invariant assertion failure, causing the mongod process to terminate abruptly. This crash removes the database from service for all connected clients until the process is manually restarted, resulting in a denial of service for applications that rely on the database.
Affected Systems
The vulnerability affects MongoDB Server from MongoDB. All installations that allow authenticated read‑only users to run aggregation commands are potentially impacted, though no specific product or version information is listed in the database.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% shows a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires user authentication with read‑only rights; it does not provide privilege escalation or remote code execution. The impact is limited to service interruption until the database is restarted, making the risk primarily a denial of service exposure. Because of the low EPSS score, immediate exploitation is unlikely, but the availability impact warrants monitoring and precautionary measures.
OpenCVE Enrichment