Impact
The vulnerability originates from an assertion in read concern processing that can be triggered by any unauthenticated network user. When the assertion’s assumptions are violated, the server process crashes, causing a denial of service for that replica set member. The flaw represents a logic error (CWE‑617) that affects availability, allowing an attacker to disrupt data replication and service continuity without needing credentials.
Affected Systems
This flaw affects MongoDB Server instances that form part of a replica set. Any replica set member that processes read concerns with the vulnerable logic may terminate when the assertion is reached. No specific version numbers are provided, so all affected builds that implement this read concern logic are at risk until patched.
Risk and Exploitability
The CVSS score of 8.7 classifies this issue as high severity, and although EPSS data is not available, the description indicates it can be exploited by simply connecting to the server without authentication. The vulnerability is not listed in the CISA KEV catalog, but the potential for widespread service disruption makes it a serious threat, especially in environments where replica sets are exposed to untrusted networks.
OpenCVE Enrichment