Privilege Escalation in MongoDB Server by Vendor MongoDB
CVE-2025-6707
4.2MEDIUM
What is CVE-2025-6707?
This vulnerability allows an authenticated user to potentially execute requests with outdated privilege levels after an authorized administrator alters permissions. The flaw exists in multiple versions of the MongoDB Server, where specific updates may leave opened pathways to exploit stale privileges, potentially leading to unauthorized access to sensitive resources or data.
Affected Version(s)
MongoDB Server 5.0 < 5.0.31
MongoDB Server 6.0 < 6.0.24
MongoDB Server 7.0 < 7.0.21
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved