Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13078

Опубликовано: 22 июл. 2026
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.39 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.28 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.2.0 (включая) до 8.2.12 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.7 (исключая)

EPSS

Процентиль: 27%
0.0034
Низкий

7.7 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 1 месяца назад

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

CVSS3: 7.7
debian
около 1 месяца назад

A vulnerability was discovered in MongoDB Server where the server-side ...

CVSS3: 7.7
github
около 1 месяца назад

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

EPSS

Процентиль: 27%
0.0034
Низкий

7.7 High

CVSS3

Дефекты

CWE-862