VYPR
High severity7.8NVD Advisory· Published Sep 15, 2025· Updated Apr 15, 2026

CVE-2025-10491

CVE-2025-10491

Description

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • MongoDB/Serverllm-fuzzy
    Range: v6.0 prior to 6.0.25, v7.0 prior to 7.0.21, v8.0 prior to 8.0.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.