SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13059

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Authenticated users with low privileges can exploit insufficient validation of client-supplied command parameters to bypass role-based query-level access controls, allowing unauthorized read and write access to sensitive data. This vulnerability impacts operations such as find, update, delete, and aggregate commands in non-apiStrict configurations. Organizations utilizing affected products should prioritize remediation to protect against potential data breaches and unauthorized data manipulation.

CVE
CVE-2026-13059
Severity
HIGH
CVSS
8.1
EPSS
0.27%

Original NVD Description

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)