Impact
An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user. An attacker who can authenticate (even with read‑only privileges) can craft a malformed index specification within that expression, causing an assertion failure in the index key generation path. In configurations where the assertion aborts the process, the mongod instance terminates, resulting in a denial of service for all connected clients.
Affected Systems
MongoDB Server is the affected product. No specific version range is provided, so all deployments that include the vulnerable internal aggregation expression are potentially impacted. The flaw is exploitable by any authenticated user, regardless of administrative rights, that has access to the aggregation framework.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, and the EPSS score is not available, so the exploitation probability is unknown but likely limited to authenticated users. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with read‑only access; the attacker submits a crafted aggregation query that includes a malformed index specification, triggering the assertion failure that may terminate the mongod process.
OpenCVE Enrichment