SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-13078

HIGH · CVSS 7.7 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB Server is vulnerable due to a flaw in the server-side MozJS scripting engine, which allows authenticated users to leverage crafted aggregation pipeline commands to read arbitrary files from the host filesystem with the privileges of the mongod process. This could lead to unauthorized access to sensitive data, posing a significant risk to data confidentiality. Organizations using MongoDB, particularly those with user authentication enabled, should prioritize addressing this vulnerability to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13078
Severity
HIGH
CVSS
7.7
EPSS
0.21%
MongoDB Java

Original NVD Description

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)