Impact
An issue in MongoDB Server’s intra-cluster connection configuration allows a network party with sufficient access to influence which authentication mechanism is selected for connections between replica set members. When the wrong mechanism is chosen, the shared internal credential can be sent without full protection; if the credential is reconstructed, an attacker can authenticate as the deployment’s superuser, gaining full control of the cluster.
Affected Systems
MongoDB Server is affected. No version range is listed in the CNA data, so the vulnerability potentially impacts all releases that rely on the default intra‑cluster authentication logic.
Risk and Exploitability
The CVSS score of 9.0 labels it a critical vulnerability, and the EPSS score of less than 1% indicates that, at the time of analysis, the likelihood of exploitation is very low but not zero. It is not listed in CISA’s KEV catalog. The attack vector is inferred to be a local network adversary with the ability to direct intra‑cluster traffic or influence authentication negotiation, rather than a remote internet attacker. If exploited, the compromised internal superuser credentials could allow an attacker to read, modify, delete, or otherwise tamper with any data within the deployment.
OpenCVE Enrichment