SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13060

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

An authenticated user with limited read privileges may exploit a flaw in the $graphLookup aggregation stage, allowing unauthorized access to documents in collections they should not be able to view. This vulnerability primarily affects scenarios involving collections referenced in existing view pipeline definitions. Organizations utilizing this aggregation feature should prioritize remediation to prevent potential data exposure.

CVE
CVE-2026-13060
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)