Impact
mongosqld requests but does not enforce a client certificate during TLS handshakes when a CA file is configured, resulting in a Client Certificate Verification Failure (CWE‑295). In environments that rely solely on client certificates for authentication, a party that can reach the listener can connect without presenting a certificate and instantly gain access to data exposed through the connector, causing a breach of confidentiality.
Affected Systems
MongoDB BI Connector with client‑certificate authentication enabled. No specific versions are listed, so all releases that allow a CA file and do not enforce client certs are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. The EPSS score is not available, and it is not yet listed in CISA’s KEV catalog. The likely attack vector is remote network access to the BI Connector listener: a malicious actor can initiate a TLS connection, omit a certificate, and when the server does not enforce it, obtain an unauthorized session that can read exposed MongoDB data.
OpenCVE Enrichment