Impact
MongoDB Server permits an authenticated user with readWrite privileges to create a collection using the WiredTiger storage engine with a custom configuration option that has an incompatible value. During collection creation, the mismatch triggers a type confusion in the storage engine. When documents are later read from the misconfigured collection, the engine attempts to interpret data with the wrong type, leading to corrupted memory dereference and causing the mongod process to crash. The crash is not transient; the incorrect configuration persists across restarts, resulting in a repeated denial of service until an operator manually corrects the collection settings.
Affected Systems
The affected product is MongoDB Server; specific version information is not provided in the vulnerability data.
Risk and Exploitability
The flaw has a CVSS score of 7.1 and does not currently appear in CISA’s KEV catalog. A user who already has authentication with readWrite rights can trigger the crash by creating a problematic collection. Because the attack requires legitimate access to the database and a custom configuration value, it is limited to internal users or compromised credentials. The resulting server crash undermines availability, making the database unusable until the misconfiguration is removed, which imposes a moderate to high risk for environments that rely on continuous data services.
OpenCVE Enrichment