jira.mongodb.org
https://jira.mongodb.org/browse/SERVER-51366 CVE-2025-10491
HIGH
MongoDB Windows installation MSI may leave ACLs unset on custom installation directories
Record summary
CVE-2025-10491 has a selected CVSS score of 7.8 (high).
Description
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB ServerBrowse MongoDB Inc / MongoDB ServerDefault status: unaffected | CVE List | 6.0 to < 6.0.25 | affected |
| 7.0 to < 7.0.21 | affected | ||
| 8.0 to < 8.0.5 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-10491