← Back to CVE search

CVE-2026-13060

MongoDB

Description

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.

CVSS 6.5EPSS 0.23600000000000002%Risk 0.66
View source
Published
2026-07-22 20:16:43
Affected versions
unknown
Type
Critical software
Last modified
2026-08-05 14:59:24
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N