STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 7.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

MongoDB must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).

DISA Rule

SV-265916r1051115_rule

Vulnerability Number

V-265916

Group Title

SRG-APP-000148-DB-000103

Rule Version

MD7X-00-003600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

For any user not a member of an appropriate organization and has access to a database in the system run the following command:

// Change to the appropriate database
> use <database>
> db.dropUser("<username>", {w: "majority", wtimeout: 5000})

The MongoDB configuration file (default location: /etc/mongod.conf) must contain the following:

security:
authorization: "enabled"

If not, edit the MongoDB configuration file. Add the parameters and stop/start (restart) any mongod or mongos process using this MongoDB configuration file.

Check Contents

For each database in the system, run the following command:

> use <database>
> db.getUsers()

Ensure each user identified is a member of an appropriate organization that can access the database.

Alternatively, if LDAP/AD is being used for authentication/authorization, the mongoldap tool can be used to verify user account access.

If a user is found not be a member of an appropriate organization that can access the database, this is a finding.

Verify that the MongoDB configuration file (default location: /etc/mongod.conf) contains the following:

security:
authorization: "enabled"

If this parameter is not present, this is a finding.

Vulnerability Number

V-265916

Documentable

False

Rule Version

MD7X-00-003600

Severity Override Guidance

For each database in the system, run the following command:

> use <database>
> db.getUsers()

Ensure each user identified is a member of an appropriate organization that can access the database.

Alternatively, if LDAP/AD is being used for authentication/authorization, the mongoldap tool can be used to verify user account access.

If a user is found not be a member of an appropriate organization that can access the database, this is a finding.

Verify that the MongoDB configuration file (default location: /etc/mongod.conf) contains the following:

security:
authorization: "enabled"

If this parameter is not present, this is a finding.

Check Content Reference

M

Target Key

5637