Privilege Escalation in MongoDB Server by Vendor MongoDB
CVE-2025-6707

4.2MEDIUM

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
26 June 2025

What is CVE-2025-6707?

This vulnerability allows an authenticated user to potentially execute requests with outdated privilege levels after an authorized administrator alters permissions. The flaw exists in multiple versions of the MongoDB Server, where specific updates may leave opened pathways to exploit stale privileges, potentially leading to unauthorized access to sensitive resources or data.

Affected Version(s)

MongoDB Server 5.0 < 5.0.31

MongoDB Server 6.0 < 6.0.24

MongoDB Server 7.0 < 7.0.21

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6707 : Privilege Escalation in MongoDB Server by Vendor MongoDB