8.8
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
Basic Information
ID
CVE-2025-11535
Source
mongodb
Published
Oct 8, 2025 at 22:07
Affected Product
Vendor
MongoDB Inc
Product
MongoDB Connector for BI
Version
2.0.0
Affected Versions
MongoDB Inc MongoDB Connector for BI 2.0.0