SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13067

MEDIUM · CVSS 6.3 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB is vulnerable when using PROXY protocol v2 on the Unix domain socket path, as it fails to properly validate roles from X.509 client certificates against the configured tlsCATrusts allow-list. This oversight can lead to unintended role assignments during MONGODB-X509 authentication, potentially compromising access controls. Organizations utilizing MongoDB with this configuration should prioritize addressing this vulnerability, especially those with local access to the proxy Unix domain socket.

CVE
CVE-2026-13067
Severity
MEDIUM
CVSS
6.3
EPSS
0.07%
MongoDB

Original NVD Description

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

Related CVEs

Other vulnerabilities affecting the same vendor(s)