SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13061

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

An authenticated user can exploit a vulnerability in the system to access session metadata of other users, which typically requires cluster-level administrative privileges. This exposure includes sensitive information such as active session identifiers, usernames, and activity timestamps, potentially leading to unauthorized access or user impersonation. Organizations utilizing the affected products should prioritize addressing this vulnerability to protect user privacy and maintain system integrity.

CVE
CVE-2026-13061
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.

Related CVEs

Other vulnerabilities affecting the same vendor(s)