LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-13078

mongodb · mongodb

Published
CVSS7.7
Severityhigh
WeaknessCWE-862
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Description

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-13078

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-13078.