Impact
The vulnerability lies in the MongoDB Server aggregation framework, where an internal command parameter can be overridden by external clients. The lack of validation allows an authenticated user with limited read privileges to circumvent view‑level authorization checks when Atlas Search is active, granting access to data from collections that should be protected. This results in a confidentiality breach and unauthorized data exposure.
Affected Systems
MongoDB Server is affected, but specific product versions are not identified in the available data. Users should verify whether their deployment includes the Atlas Search component and assess role assignments accordingly.
Risk and Exploitability
With a CVSS score of 7.1, the weakness poses significant risk. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector requires an authenticated session and the ability to construct an aggregation pipeline that targets the exposed internal command parameter. Successful exploitation would give the user read access to otherwise restricted collections.
OpenCVE Enrichment