Unvalidated Role Assignments in MongoDB through PROXY Protocol v2
CVE-2026-13067
7.2HIGH
What is CVE-2026-13067?
This vulnerability involves a failure in validating roles derived from X.509 client certificates when using PROXY protocol v2 over Unix domain sockets. If the settings allow for it, an attacker with local access can exploit improperly validated roles against the tlsCATrusts allow-list. The risk is compounded for scenarios where an attacker possesses a valid X.509 certificate from a trusted authority, leading to unauthorized role assignments during MONGODB-X509 authentication. It's crucial that systems using this setup ensure proper certificate and role validations to avoid potential exploits.
Affected Version(s)
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.3.0 < 8.3.7