Role-Based Access Control Vulnerability in MongoDB by MongoDB Inc.
CVE-2026-13059
8.6HIGH
What is CVE-2026-13059?
An access control vulnerability exists in MongoDB that could allow an authenticated user with limited privileges to perform unauthorized actions on protected data. This issue arises from insufficient validation of client-supplied command parameters in certain configurations. Affected operations include find, update, delete, and aggregate commands, potentially exposing sensitive information and undermining data protection measures.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12