Vulnerability Description
Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.24, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 5.0.0, < 5.0.31 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-93497Issue TrackingVendor Advisory
FAQ
What is CVE-2025-6707?
CVE-2025-6707 is a vulnerability with a CVSS score of 4.2 (MEDIUM). Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version...
How severe is CVE-2025-6707?
CVE-2025-6707 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-6707?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.