Privilege Escalation Vulnerability in MongoDB Connector for BI by MongoDB
CVE-2025-11535

8.8HIGH

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
8 October 2025

What is CVE-2025-11535?

The MongoDB Connector for BI on Windows, when installed via MSI, fails to set Access Control Lists (ACLs) on custom installation directories. This oversight could allow an attacker to escalate their privileges, leveraging the improperly secured installation paths. Affected versions range from 2.0.0 up to 2.14.24, making it vital for users of these versions to implement necessary security measures to mitigate potential risks.

Affected Version(s)

MongoDB Connector for BI Windows 2.0.0 <= 2.14.24

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11535 : Privilege Escalation Vulnerability in MongoDB Connector for BI by MongoDB