Impact
MongoDB Server’s query statistics serializer contains an improper conditional check that bypasses the redaction mechanism when processing search queries on the sharded cluster router. As a result, the text of search queries submitted by any user is stored in clear form and exposed through the query statistics interface. This allows an attacker who can view the statistics to read the exact query literals of other users, potentially revealing sensitive data, internal queries, or business logic, thus compromising confidentiality.
Affected Systems
MongoDB Server on sharded cluster routers is affected. No specific version information is disclosed in the advisory.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated attacker with monitoring privileges who accesses the query statistics via the router; the vulnerability requires that the attacker can read the statistics output, so the exploitation does not need arbitrary code execution but relies on existing monitoring access.
OpenCVE Enrichment