An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22
References
Link | Resource |
---|---|
https://jira.mongodb.org/browse/SERVER-106752 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Oct 2025, 20:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://jira.mongodb.org/browse/SERVER-106752 - Issue Tracking, Vendor Advisory | |
CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* | |
First Time |
Mongodb
Mongodb mongodb |
18 Jul 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22 |
08 Jul 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-07 15:15
Updated : 2025-10-03 20:49
NVD link : CVE-2025-6713
Mitre link : CVE-2025-6713
CVE.ORG link : CVE-2025-6713
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-285
Improper Authorization