CVE-2025-6711 Overview
MongoDB Server contains an information exposure vulnerability where unredacted queries may appear in server logs under specific error conditions. The flaw affects multiple release branches including v8.0 prior to 8.0.5, v7.0 prior to 7.0.18, and v6.0 prior to 6.0.21. The vulnerability is categorized under [CWE-532] Insertion of Sensitive Information into Log File. An attacker with high privileges on the database can trigger the error conditions and later access sensitive query contents through log inspection.
Critical Impact
Sensitive query data, potentially including personally identifiable information or business-critical values embedded in query filters, can be exposed through MongoDB server logs when specific error conditions occur.
Affected Products
- MongoDB Server v8.0 versions prior to 8.0.5
- MongoDB Server v7.0 versions prior to 7.0.18
- MongoDB Server v6.0 versions prior to 6.0.21
Discovery Timeline
- 2025-07-07 - CVE-2025-6711 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6711
Vulnerability Analysis
MongoDB Server writes diagnostic information to log files during normal operation and when errors occur. The server normally redacts query contents in log entries to prevent sensitive data leakage. This vulnerability breaks that guarantee under specific error paths, where the full query is written to logs without redaction. Log readers with access to server log files can therefore observe query payloads that should have been masked.
Root Cause
The root cause is an information exposure defect classified under [CWE-532]. The redaction logic that normally sanitizes query fields before writing to logs is not applied on certain error branches. When those error conditions are hit, the server serializes the original query into log output verbatim. This exposes any sensitive values embedded in the query filter, update document, or projection.
Attack Vector
Exploitation requires network access and authenticated privileges sufficient to submit queries that reach the vulnerable error paths. The impact is confidentiality-focused, with no direct effect on integrity or availability of the database. A secondary reader with access to log files, such as an operator, log-forwarding pipeline, or SIEM ingestion sink, receives the unredacted query data. See the MongoDB Jira Issue SERVER-98720 for the vendor tracking record.
No verified public exploit code is available for this issue. The vulnerability manifests within MongoDB internal error handling and query logging code paths.
Detection Methods for CVE-2025-6711
Indicators of Compromise
- Presence of MongoDB mongod.log entries containing full query documents rather than redacted placeholders during error conditions.
- Log lines referencing failed operations that include field values matching production data patterns such as email addresses, tokens, or account identifiers.
- Anomalous access patterns to MongoDB log files or log-forwarding destinations by users outside the database administration group.
Detection Strategies
- Audit MongoDB server logs for query contents that should have been redacted, focusing on error-level entries generated by vulnerable builds.
- Correlate MongoDB version banners with the fixed-version thresholds (8.0.5, 7.0.18, 6.0.21) to identify exposed instances at scale.
- Review downstream log aggregation systems for indexed fields that may now contain unredacted query payloads originating from MongoDB.
Monitoring Recommendations
- Restrict and monitor read access to MongoDB log files and any centralized log store that ingests them.
- Track privileged database user activity that generates errors, since exploitation requires authenticated access before logs are populated.
- Alert on new or unusual log-forwarding destinations configured against MongoDB hosts.
How to Mitigate CVE-2025-6711
Immediate Actions Required
- Upgrade MongoDB Server to 8.0.5, 7.0.18, or 6.0.21 or later depending on the deployed release branch.
- Rotate any credentials, tokens, or secrets that may have been present in query filters written to logs on vulnerable versions.
- Restrict access to historical log files and purge or sanitize entries containing unredacted query contents.
Patch Information
MongoDB has addressed the issue in Server versions 8.0.5, 7.0.18, and 6.0.21. Refer to the MongoDB Jira Issue SERVER-98720 for release details and cross-references.
Workarounds
- Tighten file system permissions on MongoDB log directories so only the database service account and required administrators can read them.
- Reduce log verbosity where feasible to limit the volume of error output containing query material.
- Configure log-forwarding pipelines to apply pattern-based redaction on sensitive field values before storage or indexing.
# Verify installed MongoDB Server version
mongod --version
# Restrict permissions on MongoDB log directory
chown -R mongodb:mongodb /var/log/mongodb
chmod 750 /var/log/mongodb
chmod 640 /var/log/mongodb/mongod.log
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
