Impact
An authenticated user who has write access to a time‑series collection that uses a metaField in MongoDB Server can submit a query with certain predicates that causes the server process to terminate unexpectedly. The failure results in a denial of service that affects the availability of the database system for all users. The weakness is based on improper input validation as identified by CWE‑617.
Affected Systems
MongoDB Server time‑series collections using a metaField; the CVE does not specify affected versions, so the precise scope of affected releases is unknown.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, indicating a moderate risk. The EPSS score is less than 1 %, suggesting that exploitation is unlikely at present, and the issue is not listed in the CISA KEV catalog. The attack requires authenticated write access to the target collection; no known public exploits exist, but an insider or compromised account could trigger the denial of service.
OpenCVE Enrichment