CVE-2026-25613
CVE-2026-25613 is a medium-severity vulnerability in Mongodb with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-704.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 7.1
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-6759
- Weakness: CWE-704
- Affected product: Mongodb
- Published:
- Last modified:
Description
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
Frequently asked questions
- What is CVE-2026-25613?
- An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
- How severe is CVE-2026-25613?
- CVE-2026-25613 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-25613 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-25613?
- CVE-2026-25613 affects Mongodb. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-25613?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-25613 have an EU (EUVD) identifier?
- Yes. CVE-2026-25613 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-6759.
- When was CVE-2026-25613 published?
- CVE-2026-25613 was published on 2026-02-10 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
More vulnerabilities in Mongodb
- CVE-2017-15535 — Critical (CVSS 9.1): MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting,…
- CVE-2026-18692 — High (CVSS 8.8): An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write…
- CVE-2026-18691 — High (CVSS 8.8): An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to…
- CVE-2026-11933 — High (CVSS 8.8): A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents…
- CVE-2026-8053 — High (CVSS 8.8): An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write…
- CVE-2026-4148 — High (CVSS 8.8): A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who…
Other CWE-704 (Incorrect Type Conversion or Cast) vulnerabilities
- CVE-2015-3120 — Critical (CVSS 10.0): Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before…
- CVE-2026-58822 — Critical (CVSS 9.8): In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead…
- CVE-2026-15826 — Critical (CVSS 9.8): The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up…
- CVE-2025-39880 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: libceph: fix invalid accesses to…
- CVE-2025-41648 — Critical (CVSS 9.8): An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it…
- CVE-2025-41646 — Critical (CVSS 9.8): An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect…
Browse all CWE-704 (Incorrect Type Conversion or Cast) vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 103.7.41.117 (ipv4-addr)
- 1.234.27.159 (ipv4-addr)
- 70.81.127.119 (ipv4-addr)
- 54.37.10.124 (ipv4-addr)
- 98.70.52.248 (ipv4-addr)
- 167.71.60.5 (ipv4-addr)
- 106.12.70.210 (ipv4-addr)
- 103.74.121.154 (ipv4-addr)