← Vulnerability feed

Vulnerability record · CVE-2024-7553 · published 7 August 2024

CVE-2024-7553: Mongodb improper access control vulnerability

Mongodb · Mongodb

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue

7.8 CVSS 3.1 High EPSS 0.26% · top 84.1% CWE-284 · Improper access control
7.8CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7553 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-14847MongoDB Server heap memory disclosure via compressed protocol headersMismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Ser…KEVEPSS 83%analysed9.8CVE-2025-3085Mongodb vulnerabilityA MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…EPSS 0.27%9.8CVE-2024-8654Mongodb use of uninitialized resource vulnerabilityMongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…EPSS 0.37%9.8CVE-2024-1351Mongodb improper certificate validation vulnerabilityUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…EPSS 0.50%9.2CVE-2026-82067Mongodb vulnerabilityImproper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in …EPSS 0.51%9.2CVE-2026-13072Mongodb heap-based buffer overflow vulnerabilityWhen compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…EPSS 0.40%9.1CVE-2017-15535Mongodb vulnerabilityMongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…EPSS 1.6%9.0CVE-2026-18691Mongodb vulnerabilityAn issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2024-7553), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.