Unvalidated Role Assignments in MongoDB through PROXY Protocol v2
CVE-2026-13067

7.2HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13067?

This vulnerability involves a failure in validating roles derived from X.509 client certificates when using PROXY protocol v2 over Unix domain sockets. If the settings allow for it, an attacker with local access can exploit improperly validated roles against the tlsCATrusts allow-list. The risk is compounded for scenarios where an attacker possesses a valid X.509 certificate from a trusted authority, leading to unauthorized role assignments during MONGODB-X509 authentication. It's crucial that systems using this setup ensure proper certificate and role validations to avoid potential exploits.

Affected Version(s)

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.3.0 < 8.3.7

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.