CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22
References
Link Resource
https://jira.mongodb.org/browse/SERVER-106752 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

03 Oct 2025, 20:49

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-106752 - () https://jira.mongodb.org/browse/SERVER-106752 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
First Time Mongodb
Mongodb mongodb

18 Jul 2025, 06:15

Type Values Removed Values Added
Summary (en) An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.20 and MongoDB Server v6.0 versions prior to 6.0.22 (en) An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Un usuario no autorizado podría usar una canalización de agregación especialmente manipulada para acceder a los datos sin la debida autorización debido a la gestión incorrecta de la etapa $mergeCursors en MongoDB Server. Esto puede provocar el acceso a los datos sin autorización adicional. Este problema afecta a MongoDB Server v8.0 anteriores a la 8.0.7, MongoDB Server v7.0 anteriores a la 7.0.20 y MongoDB Server v6.0 anteriores a la 6.0.22.

07 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 15:15

Updated : 2025-10-03 20:49


NVD link : CVE-2025-6713

Mitre link : CVE-2025-6713

CVE.ORG link : CVE-2025-6713


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-285

Improper Authorization