Impact
The vulnerability stems from improper handling of case sensitivity in MongoDB Server’s configuration validation component. This defect allows the authorization subsystem to remain disabled on startup, enabling any unauthenticated user with network access to perform arbitrary administrative operations. The impact encompasses full compromise of data confidentiality, integrity, and availability, and the underlying weakness is identified as CWE‑178.
Affected Systems
MongoDB Server is the affected product. No specific version information is provided, so all releases that include the flawed configuration validation logic are potentially susceptible until a fix is applied.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated network access to a MongoDB deployment where the configuration validation flaw exists, allowing an attacker to start the authentication subsystem in a disabled state and perform privileged actions. Exploitation conditions appear minimal, requiring only network connectivity to the MongoDB instance.
OpenCVE Enrichment