Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.
Required Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mongodb50Upgrade mongodb70Upgrade mongodb60Upgrade mongodb44 | Dec 10, 2025 | Mar 20, 2024 |
| Mongodb | — | Upgrade MongoDB to version 6.0.14Upgrade to the latest version of MongoDBUpgrade MongoDB to version 5.0.25Upgrade MongoDB to version 4.4.29Upgrade MongoDB to version 7.0.6 | Mar 13, 2025 | Mar 7, 2024 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.4.4Upgrade Splunk Enterprise to version 9.3.6Upgrade Splunk Enterprise to version 9.2.8Upgrade Splunk Enterprise to version 10.0.1 | Jul 30, 2026 | Mar 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub