CVE-2025-6707
Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.24, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5.
- Affected products
- Alt Linux, Mongodb Server, Mongodb, Red Os
- Mongodb
- < 5.0.31, 6.0.24, 7.0.21, 8.0.5
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.1% (4th percentile)
- Weakness
- CWE-863
- NVD status
- Analyzed
- Published
- 2025-06-26
CVE-2025-6707 at NVD
No indexed exploits for CVE-2025-6707 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-6707 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.