Missing Authorization in MongoDB Server - CVE-2026-13078
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the MozJS scripting engine module loader when processing crafted aggregation pipeline commands. A remote user can submit crafted aggregation pipeline commands containing JavaScript to read sensitive files accessible to the MongoDB server process to disclose sensitive information.
The issue allows access to files from the host filesystem using the mongod process's privileges.