CVE-2026-13060

MEDIUM

$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access

Title source: cna
STIX 2.1

Description

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (4)
MongoDB/MongoDB Server 7.0 - 7.0.39
MongoDB/MongoDB Server 8.0 - 8.0.28
MongoDB/MongoDB Server 8.2.0 - 8.2.12
MongoDB/MongoDB Server 8.3.0 - 8.3.7
Published Jul 22, 2026
Tracked Since Jul 23, 2026