Incorrect authorization in MongoDB Server - CVE-2026-13061
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the $listSessions aggregation stage when handling aggregation requests. A remote user can query session metadata for other users to disclose sensitive information.
The disclosed data includes active session identifiers, associated usernames, and activity timestamps.