Impact
A use‑after‑free flaw in MongoDB Server’s timeseries bucket lifecycle handling can let an authenticated user with write privileges trigger an internal reference to be used after its memory has been freed. This defect may cause the server to crash or, under certain conditions, execute unintended code, leading to both availability loss and a possible remote code execution vector.
Affected Systems
The vulnerability affects MongoDB Server. No specific version information is provided, so any deployment that runs the vulnerable timeseries bucket handling can be impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS score is below 1%, suggesting that exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog. Exploitation would require an authenticated user with sufficient write rights; if achieved, the attacker could disrupt service or gain code execution capability.
OpenCVE Enrichment