CVE-2026-13078

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-128832 Vendor Advisory Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-22 20:16

Updated : 2026-08-18 16:06


NVD link : CVE-2026-13078

Mitre link : CVE-2026-13078

CVE.ORG link : CVE-2026-13078


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-862

Missing Authorization