An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations.
{
"cwe_ids": [
"CWE-807"
],
"cna_assigner": "mongodb",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13059.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "7.0"
},
{
"fixed": "7.0.39"
},
{
"introduced": "8.0"
},
{
"fixed": "8.0.28"
},
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.12"
},
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.7"
}
]
}
]
}{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.39"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.28"
},
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.12"
},
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.7"
}
],
"cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13059.json"
"2026-08-07T08:11:18Z"
[
{
"digest": {
"line_hashes": [
"195283451325379709791176466181059330449",
"11934503373533753673416013101293166641",
"34761259574797342523983725962110135860",
"6697845561671035843872382804131271398",
"190799824288394015190372324041271803151"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-13059-18a7c7d6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/10d50f5046de5c76a9d869823219134b3596905a",
"target": {
"file": "src/mongo/db/pipeline/javascript_execution.cpp"
}
},
{
"digest": {
"length": 419.0,
"function_hash": "139145742414386593281199011500928031122"
},
"deprecated": false,
"id": "CVE-2026-13059-309120cf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/10d50f5046de5c76a9d869823219134b3596905a",
"target": {
"function": "JsExecution::callFunction",
"file": "src/mongo/db/pipeline/javascript_execution.cpp"
}
},
{
"digest": {
"line_hashes": [
"235349502426767986109171624443399362060",
"332118117976299452680602889698335846937",
"273414055616980281623380822972213976202",
"260359270913691981069265618939534968152",
"92760588891291927255272146911062451930",
"131421526859279654507125979858138582212"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-13059-cb3d2fa4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/10d50f5046de5c76a9d869823219134b3596905a",
"target": {
"file": "src/mongo/scripting/mozjs/objectwrapper.cpp"
}
},
{
"digest": {
"line_hashes": [
"39839291339635135228351456498984914983",
"35727036334983502474101853618146564071",
"152433407413412697966849125832082995516"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-13059-e13fbe7c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/10d50f5046de5c76a9d869823219134b3596905a",
"target": {
"file": "src/mongo/db/pipeline/expression_javascript_test.cpp"
}
},
{
"digest": {
"length": 1418.0,
"function_hash": "284447201108016139902358258055612064237"
},
"deprecated": false,
"id": "CVE-2026-13059-e30fe2e5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/10d50f5046de5c76a9d869823219134b3596905a",
"target": {
"function": "ObjectWrapper::toBSON",
"file": "src/mongo/scripting/mozjs/objectwrapper.cpp"
}
}
]