Authentication Flaw in MongoDB Affects User Privileges Across Databases
CVE-2026-13068

2.3LOW

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13068?

An authentication flaw in MongoDB allows users with cursor termination privileges on one database to terminate active cursors on another database. This misconfiguration leading to improper authorization checks can disrupt ongoing query operations for other users, thereby affecting database performance and availability. It's vital for administrators to review privilege assignments to ensure that user access is correctly scoped within individual database namespaces.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.2.0 < 8.2.12

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.