CVE-2026-13059 | MongoDB Server up to 7.0.38/8.0.27/8.2.11/8.3.6 non-apiStrict configuration find/update/delete/aggregate access control

SecurityVulns

A vulnerability identified as critical has been detected in MongoDB Server up to 7.0.38/8.0.27/8.2.11/8.3.6. Affected by this issue is the function find/update/delete/aggregate of the component non-apiStrict configuration. This manipulation causes improper access controls.

This vulnerability is registered as CVE-2026-13059. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More