Threats Tagged 'cve-2026-13061'
View all threats tagged with 'cve-2026-13061'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-13061'
Click on any threat for detailed analysis and mitigation recommendations
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. (CVE-2026-13061)CVE-2026-13061 0 An authenticated user may be able to access session metadata of other users via the $listSessions aggregation stage. This metadata, normally restricted to cluster-level administrators, includes active session IDs, usernames, and activity timestamps. The vulnerability represents an authorization bypass issue allowing access to sensitive session information without proper privileges. Join the discussion | GCVE Database | 07/22/2026, 21:32:06 UTC Added: 07/22/2026, 23:23:08 UTC |
CVE-2026-13061: CWE-863: Incorrect Authorization in MongoDB MongoDB ServerCVE-2026-13061 0 An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps. Join the discussion | CVE Database V5 | 07/22/2026, 19:19:34 UTC Added: 07/22/2026, 20:07:58 UTC |
Showing 1 to 2 of 2 results