Impact
An authenticated user possessing a limited database‑scoped role can exploit a MongoDB Server flaw that allows them to act against protected system collections they normally would not be authorized to touch. The vulnerability stems from improper authorization checks (CWE‑863) and could lead to dropping and recreating critical system collections, disrupting database operation and potentially causing data loss or service downtime.
Affected Systems
The flaw affects MongoDB Server deployments that have not applied the published fix; no specific version range is listed in the CVE, so security teams should verify all running server versions against the MongoDB security advisories.
Risk and Exploitability
The CVSS base score of 7.2 marks the issue as high severity, while an EPSS of less than 1% indicates a low probability of exploitation today. This vulnerability requires the attacker to be authenticated with a role that has standard database access. Based on the description, the likely attack vector is an authenticated database user, not remote unauthenticated access. Though not yet in the CISA KEV catalog, the potential for data loss and service disruption warrants prompt attention.
OpenCVE Enrichment