What is CVE-2026-13078?
A vulnerability in MongoDB Server's server-side MozJS scripting engine allows authenticated users to read arbitrary files from the host filesystem via JavaScript calls. Updating MongoDB to the latest version is recommended to mitigate this issue.
Azərbaycanca: MongoDB Server-in server-side MozJS skript mühərrikində boşluq aşkarlanıb. Autentifikasiya olunmuş istifadəçi JavaScript çağırışları ilə host sistemindən ixtiyari faylları oxuya bilər. Mühafizə üçün MongoDB-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
Is authentication required to exploit CVE-2026-13078 in MongoDB Server?
Yes, an authenticated user can read arbitrary files from the host filesystem.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.