Impact
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This results in an authentication bypass that defeats administrative intent, representing a CWE-863 vulnerability.
Affected Systems
MongoDB Server is the affected product. No specific version information is provided, so any installation configured to restrict authentication yet still enabling certificate-based authentication may be vulnerable.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score is below 1%, suggesting a very low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector involves an attacker who possesses a valid client certificate and network access to the server; they can exploit the server’s misconfiguration to authenticate via the disabled method and gain privileges they otherwise would not have.
OpenCVE Enrichment