SimStudio MongoDB Unauthorized Access and Data Manipulation Vulnerability
Vulnerability
A vulnerability exists in SimStudio versions prior to 0.5.74, where the MongoDB tool endpoints allow arbitrary connection parameters without authentication or host restrictions. This flaw enables attackers to connect to any accessible MongoDB instance and execute unauthorized actions, such as reading, modifying, and deleting data.
Impact
Exploitation of this vulnerability could lead to unauthorized access and manipulation of data in MongoDB databases, including arbitrary deletion of documents.
Remediation
Users are advised to upgrade to SimStudio version 0.5.74 or later.
Added: Mar 2, 2026, 1:18 PM
Updated: Mar 2, 2026, 1:18 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.7exploitability
7.4remediation
0.0relevance
3.4threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
