Impact
An authenticated attacker who can write to a MongoDB database can trigger a time-series bucket catalog inconsistency that causes an out-of-bounds memory write. This flaw enables arbitrary code execution within the mongod process, potentially giving the attacker full control over the database server. The weakness is a classic memory-safety issue.
Affected Systems
MongoDB Server is affected. Versions prior to 5.0.33, 6.0.28, 7.0.34, 8.0.23, 8.2.9 and 8.3.2 are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. No EPSS data is presently available, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with write privileges to the database, suggesting that the attack vector is limited to logged‑in users with sufficient permissions.
OpenCVE Enrichment