CVE-2025-13643
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-25
Last updated on: 2025-12-11
Assigner: MongoDB, Inc.
Description
Description
A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mongodb | mongodb | From 7.0.0 (inc) to 7.0.26 (exc) |
| mongodb | mongodb | From 8.0.0 (inc) to 8.0.14 (exc) |
| mongodb | mongodb | 8.2.0 |
| mongodb | mongodb | 8.2.0 |
| mongodb | mongodb | 8.2.0 |
| mongodb | mongodb | 8.2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |