Authentication Flaw in MongoDB Affects User Privileges Across Databases
CVE-2026-13068
2.3LOW
What is CVE-2026-13068?
An authentication flaw in MongoDB allows users with cursor termination privileges on one database to terminate active cursors on another database. This misconfiguration leading to improper authorization checks can disrupt ongoing query operations for other users, thereby affecting database performance and availability. It's vital for administrators to review privilege assignments to ensure that user access is correctly scoped within individual database namespaces.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12