Incorrect authorization in MongoDB Server - CVE-2026-13067

 

Incorrect authorization in MongoDB Server - CVE-2026-13067

Published: August 18, 2026


Vulnerability identifier: #VU144116
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13067
CWE-ID: CWE-863
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to obtain unintended role assignments.

The vulnerability exists due to incorrect authorization in tlsCATrusts role validation on the Unix domain socket path when using PROXY protocol v2 with MONGODB-X509 authentication. A local user can connect through the proxy Unix domain socket with a valid X.509 certificate issued by a trusted certificate authority to obtain unintended role assignments.

Exploitation requires local access to the proxy Unix domain socket.


Affected software

MongoDB Server

How to mitigate CVE-2026-13067

Install security update from vendor's website.

MongoDB Server - addressed in versions 8.0.28, 8.3.7

External References

Related Security Bulletins