Session Metadata Exposure in MongoDB by MongoDB, Inc.
CVE-2026-13061
5.3MEDIUM
What is CVE-2026-13061?
An authenticated user in the MongoDB environment can potentially access session metadata for other users through the $listSessions aggregation stage. This access is typically restricted to users with cluster-level administrative privileges. The exposed information may include active session identifiers, associated usernames, and timestamps of user activity, raising significant privacy and security concerns.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.3.0 < 8.3.7