Incorrect authorization in MongoDB Server - CVE-2026-13067
Published: August 18, 2026
Vulnerability details
The vulnerability allows a local user to obtain unintended role assignments.
The vulnerability exists due to incorrect authorization in tlsCATrusts role validation on the Unix domain socket path when using PROXY protocol v2 with MONGODB-X509 authentication. A local user can connect through the proxy Unix domain socket with a valid X.509 certificate issued by a trusted certificate authority to obtain unintended role assignments.
Exploitation requires local access to the proxy Unix domain socket.