Incorrect authorization in MongoDB Server - CVE-2026-13060
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the $graphLookup aggregation stage when evaluating authorization and execution for collections referenced within existing view pipeline definitions. A remote user can query a view that references unauthorized collections to disclose sensitive information.
Only affected scenarios involving collections referenced within existing view pipeline definitions are exposed.