Impact
An authenticated member of a MongoDB Ops Manager organization can use user-listing endpoints to retrieve another member's pending authenticator enrollment seed while that member’s enrollment is unconfirmed. This disclosure of the secret authentication material could allow the requesting member to bypass MFA or otherwise compromise the target account. The weakness is a classic Authentication Information Disclosure (CWE-201).
Affected Systems
MongoDB Ops Manager. Version information was not specified in the CNA data, so the issue applies to the release containing the vulnerable user‑listing endpoints.
Risk and Exploitability
The CVSS base score of 6.0 indicates medium severity. EPSS data is unavailable, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user within the same organization; therefore the attack surface is limited to internal members, but the exposed MFA seed could enable account takeover or bypass of security controls.
OpenCVE Enrichment