Incorrect authorization in MongoDB Server - CVE-2026-13061

 

Incorrect authorization in MongoDB Server - CVE-2026-13061

Published: August 18, 2026


Vulnerability identifier: #VU144122
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13061
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the $listSessions aggregation stage when handling aggregation requests. A remote user can query session metadata for other users to disclose sensitive information.

The disclosed data includes active session identifiers, associated usernames, and activity timestamps.


Affected software

MongoDB Server

How to mitigate CVE-2026-13061

Install security update from vendor's website.

MongoDB Server - addressed in versions 7.0.39, 8.0.28, 8.3.7

External References

Related Security Bulletins