PT-2026-63465 · Mongodb+3 · Mongodb+2

CVE-2026-13061

·

Published

2026-07-22

·

Updated

2026-08-17

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An authenticated user can access session metadata of other users via the $listSessions aggregation stage. This data, which includes active session identifiers, associated usernames, and activity timestamps, is typically restricted to users with cluster-level administrative privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MONGODB-2026-13061
CVE-2026-13061

Affected Products

Mongodb
Mongodb Server
Mongo