Impact
MongoDB Server allows an authenticated user with minimal privileges to create a specially formatted aggregation request that misleads the authorization subsystem into evaluating an unauthorized operation, resulting in read access to collection data not intended for that user. This confidentiality breach, driven by an Incorrect Authorization flaw (CWE-863), exposes the contents of target databases to users who should not have that visibility.
Affected Systems
MongoDB Server is affected. No specific product versions are listed, so all active installations of MongoDB Server are potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a medium to high severity. The EPSS score is not available, and it is not currently listed in CISA’s KEV catalog. Exploitation requires only authentication with minimal privileges and likely occurs over the network, making it a moderate risk for organizations that allow authenticated aggregation queries. The attack vector is inferred to be an authenticated user crafting a request; no external exploitation conditions are explicitly stated.
OpenCVE Enrichment