CVE-2026-13067

MEDIUM

tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket

Title source: cna
STIX 2.1

Description

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

References (1)

Core 1

Scores

CVSS v3 6.3
EPSS 0.0007
EPSS Percentile 0.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
MongoDB/MongoDB Server 8.0 - 8.0.28
MongoDB/MongoDB Server 8.3.0 - 8.3.7
Published Jul 22, 2026
Tracked Since Jul 23, 2026