Back to overview

CVE-2026-13067

MEDIUM
6.3
CVSS 3.1
Description
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

Metadata

CVE ID
CVE-2026-13067
State
PUBLISHED
Assigner
mongodb
Reserved
2026-06-23 18:00 UTC
Published
2026-07-22 19:16 UTC
Last updated
2026-07-22 19:16 UTC
Primary CWE
CWE-863
CWE-863: Incorrect Authorization
Vendor / Product
MongoDB / MongoDB Server
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
MongoDB MongoDB Server 8.0 < 8.0.28, 8.3.0 < 8.3.7
Weakness (CWE)
CWESourceDescription
CWE-863 cna CWE-863: Incorrect Authorization
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.2 HIGH 4.0 cna CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
6.3 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Back to overview