Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-128433 |
|
Fri, 24 Jul 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb Server |
|
| Vendors & Products |
Mongodb
Mongodb mongodb Server |
Wed, 22 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations. | |
| Title | Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-07-24T03:56:11.586Z
Reserved: 2026-06-23T18:00:01.964Z
Link: CVE-2026-13059
Updated: 2026-07-23T14:24:32.753Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-26T05:00:08Z