7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
Basic Information
ID
CVE-2026-25613
Source
mongodb
Published
Feb 10, 2026 at 18:54
Modified
Feb 10, 2026 at 19:15
Affected Product
Vendor
MongoDB Inc
Product
MongoDB Server
Version
7.0
Affected Versions
MongoDB Inc MongoDB Server 7.0
MongoDB Inc MongoDB Server 8.0
MongoDB Inc MongoDB Server 8.2
MongoDB Inc MongoDB Server 8.0
MongoDB Inc MongoDB Server 8.2