Missing Authorization in MongoDB Server - CVE-2026-13078

 

Missing Authorization in MongoDB Server - CVE-2026-13078

Published: August 18, 2026


Vulnerability identifier: #VU144105
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13078
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the MozJS scripting engine module loader when processing crafted aggregation pipeline commands. A remote user can submit crafted aggregation pipeline commands containing JavaScript to read sensitive files accessible to the MongoDB server process to disclose sensitive information.

The issue allows access to files from the host filesystem using the mongod process's privileges.


Affected software

MongoDB Server

How to mitigate CVE-2026-13078

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.39, 8.0.28, 8.2.12, 8.3.7

External References

Related Security Bulletins