Junglewise Threat Intelligence

CVE-2026-13057: MongoDB Server access control bypass in Atlas Search integration

CVE-2026-13057 · Severity: medium · CVSS 5.3 · Published 2026-07-22

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

A security flaw in MongoDB's Atlas Search integration allows an authorized user to bypass access controls and view data they should not be able to see. This occurs in specific database configurations where data is split across multiple servers (sharding). An attacker could exploit this to access sensitive information, potentially leading to unauthorized data exposure.

Technical details

An improper input validation vulnerability exists in MongoDB Server's Atlas Search integration ($search and $searchMeta aggregation stages). In sharded topologies, these stages rely on internal routing fields that are intended to be populated only by a trusted router. However, due to insufficient validation, an authenticated client can manually supply these internal fields (specifically mergingPipeline). This allows the attacker to bypass typical validation steps and per-user access controls to retrieve unauthorized data. The vulnerability affects MongoDB Server versions 8.0.x, 8.2.x, and 8.3.x, and is addressed in versions 8.0.28, 8.2.12, and 8.3.7.

Affected products

  • MongoDB MongoDB Server 8.0 before 8.0.28, 8.2 before 8.2.12, 8.3 before 8.3.7

Timeline

  • 2026-05-07: other: Issue reported internally in MongoDB Jira
  • 2026-07-22: disclosed: CVE published to NVD

References