MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
History

Wed, 08 Oct 2025 22:15:00 +0000

Type Values Removed Values Added
Description MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
Title MongoDB Connector for BI installation MSI leave ACLs unset on custom installation directories
Weaknesses CWE-276
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-10-08T22:07:18.498Z

Reserved: 2025-10-08T21:16:03.837Z

Link: CVE-2025-11535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-08T22:15:32.557

Modified: 2025-10-08T22:15:32.557

Link: CVE-2025-11535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.