Security Advisory

CVE-2026-13061

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-22 19:19:34
Last updated 2026-07-23 14:23:48
Assigner mongodb
CVSS score 5.3
State PUBLISHED

Description

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.