Impact
An authenticated MongoDB Server user with elevated internal privileges can bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that is not intended to be client‑selectable. This bypass allows execution of container operations that are disabled by default in production configurations, enabling direct storage‑engine writes to arbitrary internal storage tables. The authorization check for these operations validates only the operation’s namespace, not the actual storage target, so the attacker can write to unrelated internal metadata or other collections’ data.
Affected Systems
MongoDB Server is the affected product. No specific version range is listed in the CNA data, implying that any deployment of MongoDB Server could be vulnerable until a patch is applied. The vulnerability requires authenticated internal privileged access, so it applies to users who hold elevated internal roles within the cluster.
Risk and Exploitability
The CVSS score of 7 indicates high severity, though the EPSS score is not available and the issue is not listed in CISA KEV, suggesting limited public exploitation data. The attack vector requires internal privileged credentials, so the risk is moderate to high for organizations that have such accounts. An attacker who can gain authenticated internal privileged access can modify internal tables, potentially corrupt data, trigger a denial of service, or use the foothold for broader compromise.
OpenCVE Enrichment