Server-Side Scripting Vulnerability in MongoDB Server
CVE-2026-13078

6.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13078?

A vulnerability in MongoDB Server's server-side MozJS scripting engine allows an authenticated user to exploit crafted aggregation pipeline commands, enabling unauthorized access to sensitive files on the host filesystem. This occurs because the module loading hook for the scripting engine registers unconditionally, which poses a security risk by granting the mongod process's privileges for file access. Attackers can leverage this vulnerability to read files that are otherwise restricted, increasing the potential impact on data privacy and integrity.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.2.0 < 8.2.12

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.