P-2664.msi: A high-severity security vulnerability has been identified in the MongoDB component utilized by the Rapid Recovery Core. This flaw, tracked as CVE-2025-14847 (also known as "MongoBleed"), allows unauthenticated remote attackers to read uninitialized heap memory, potentially exposing sensitive data such as credentials or session tokens. We have released patch P-2664, which remediates this vulnerability by upgrading the internal MongoDB instance to version 7.0.28.
For more details, please see solution SOL4381740 in our Knowledge Base.