Search
Search Results (25 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13061 | 1 Mongodb | 2 Mongodb, Mongodb Server | 2026-07-23 | 4.3 Medium |
| An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps. | ||||
| CVE-2026-13057 | 1 Mongodb | 2 Mongodb, Mongodb Server | 2026-07-23 | 5.3 Medium |
| An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded search planning. Due to insufficient input validation, an authenticated client can supply these fields directly. | ||||
| CVE-2026-9737 | 1 Mongodb | 1 Mongodb Server | 2026-07-23 | 6.5 Medium |
| During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure. | ||||
| CVE-2026-13062 | 1 Mongodb | 2 Mongodb, Mongodb Server | 2026-07-23 | 6.5 Medium |
| An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness. | ||||
| CVE-2026-13060 | 1 Mongodb | 2 Mongodb, Mongodb Server | 2026-07-23 | 6.5 Medium |
| An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions. | ||||