CVE-2026-13078 – MongoDB Server

CVSS 7.7 IMPORTANT High with EoP or RCE – Expedited Deployment

“Strong access controls only matter when every layer enforces them consistently.”

This MongoDB Server security update resolves four High severity vulnerabilities affecting query processing, BSON parsing, JavaScript execution, and aggregation pipeline handling. The fixes strengthen validation of client-supplied data, improve memory safety, enforce access controls, and prevent unintended access to sensitive resources. Together, these updates reduce the risk of unauthorized data access, information disclosure, memory corruption, and service instability.

CVE-2026-13059 has a CVSS score of 8.1, High severity, and resolves insufficient validation of client-supplied command parameters that could allow an authenticated low-privileged user to bypass role-based query-level access controls. CVE-2026-13072 has a CVSS score of 8.1, High severity, and corrects a memory corruption vulnerability during aggregation pipeline processing when compute mode is explicitly enabled. CVE-2026-13077 has a CVSS score of 7.1, High severity, and fixes an out-of-bounds heap read that could lead to server crashes or disclosure of adjacent memory. CVE-2026-13078 has a CVSS score of 7.7, High severity, and prevents authenticated users from reading arbitrary files through the server-side JavaScript engine.

Key Details

Affected Product
Mongodb Mongodb
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.