MongoDBCVE-2026-13067
MongoDB Server: improper authorization
High7.2CVE-2026-13067 · Published Jul 22, 2026 · updated Aug 5, 2026
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MongoDB Server Product | >= 8.0, < 8.0.28 | 8.0.28 |
| >= 8.3.0, < 8.3.7 | 8.3.7 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 22 | MongoDB Server: reachable assertion | High7.1 | 7.0.39+3 more |
| Jul 22 | MongoDB Compass: command injection | High8.4 | 1.49.7 |
| Jul 22 | MongoDB Server: resource exhaustion | Medium6.9 | 7.0.39+3 more |
| Jul 22 | MongoDB Server: resource exhaustion | High7.1 | 8.2.12+1 more |
| Jul 22 | MongoDB Server: resource exhaustion | High7.1 | 8.3.7 |
| Jul 22 | MongoDB Server: out-of-bounds read | High7.1 | 7.0.39+3 more |