CVE-2025-11535: MongoDB Inc MongoDB Connector For BI
High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
Affected products
- MongoDB Inc MongoDB Connector For BI: from 2.0.0, up to and including 2.14.24
Published 2025-10-08. Last modified 2026-10-08.