Impact
The vulnerability is located in the storage engine integration layer of MongoDB Server, allowing an authenticated user with collection creation privileges to supply storage configuration options that bypass validation. The invalid options are written to durable metadata; when the metadata is later read by diagnostic operations a fatal assertion failure occurs, causing a persistent denial of service. The weakness is identified as CWE‑617 (Unchecked Input for Assembly Generation).
Affected Systems
MongoDB Server is impacted. No specific versions are cited in the advisory, so any deployed instance of MongoDB Server could potentially be affected until the issue is patched. The vulnerability requires the user to have authentication and collection creation rights.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers need authenticated access with collection creation privileges, after which they can corrupt metadata that persists across restarts and propagates to replica set members. Manual operator intervention is required to restore service, so the impact on availability is significant and remediation is time-consuming.
OpenCVE Enrichment