Session Metadata Exposure in MongoDB by MongoDB, Inc.
CVE-2026-13061

5.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13061?

An authenticated user in the MongoDB environment can potentially access session metadata for other users through the $listSessions aggregation stage. This access is typically restricted to users with cluster-level administrative privileges. The exposed information may include active session identifiers, associated usernames, and timestamps of user activity, raising significant privacy and security concerns.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.3.0 < 8.3.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.