Skip to content
MongoDBCVE-2026-13068

MongoDB Server: improper authorization

Low2.3CVE-2026-13068 · Published Jul 22, 2026 · updated Aug 5, 2026

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.

MongoDB advisory

Affected versions

PackageAffectedFixed in
MongoDB Server
Product
>= 7.0, < 7.0.397.0.39
>= 8.0, < 8.0.288.0.28
>= 8.2.0, < 8.2.128.2.12
>= 8.3.0, < 8.3.78.3.7
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More MongoDB advisories

All MongoDB
Advisory
MongoDB Server: reachable assertion
High7.1Jul 22
MongoDB Compass: command injection
High8.4Jul 22
MongoDB Server: resource exhaustion
Medium6.9Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: out-of-bounds read
High7.1Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.