Server-Side Scripting Vulnerability in MongoDB Server
CVE-2026-13078
6.3MEDIUM
What is CVE-2026-13078?
A vulnerability in MongoDB Server's server-side MozJS scripting engine allows an authenticated user to exploit crafted aggregation pipeline commands, enabling unauthorized access to sensitive files on the host filesystem. This occurs because the module loading hook for the scripting engine registers unconditionally, which poses a security risk by granting the mongod process's privileges for file access. Attackers can leverage this vulnerability to read files that are otherwise restricted, increasing the potential impact on data privacy and integrity.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12