Impact
The vulnerability is an out‑of‑bounds read/write flaw in the Timeseries bucket handling logic of MongoDB Server. When an authenticated user with write privileges inserts certain documents, the internal bucket structure can become inconsistent. A subsequent insert may then cause the server to access memory outside its intended bounds, leading to a crash (denial of service), exposure of limited memory contents, or memory corruption. The weakness is identified as CWE‑787.
Affected Systems
MongoDB Server is affected. No version information was provided in the advisory.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high severity level, while the EPSS score of less than 1 percent suggests that exploitation is currently considered rare. The vulnerability requires authentication and write privileges to a timeseries collection, so the attack vector is likely local. It is not listed in the CISA KEV catalog, implying no publicly documented exploit has been observed yet. Nonetheless, a successful exploit would result in service interruption and potential data leakage.
OpenCVE Enrichment