What is CVE-2026-13057?
This flaw allows an authenticated user to bypass per-user access controls in the server's Atlas Search integration via the `$search` and `$searchMeta` aggregation stages, specifically in sharded topologies due to improper internal routing. Affected users must immediately apply the security patch provided by the vendor to mitigate unauthorized data access.
Azərbaycanca: Bu boşluq autentifikasiya olunmuş istifadəçiyə serverin Atlas Search inteqrasiyasında `$search` və `$searchMeta` aqreqasiya mərhələləri vasitəsilə hər istifadəçiyə təyin olunmuş giriş nəzarətini yan keçməyə imkan verir. Zəiflik xüsusilə şardlanmış topologiyalarda daxili rutinq mexanizminin etibarsız istifadəsi nəticəsində yaranır. Təsirə məruz qalan sistemlərdə təcili olaraq istehsalçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
In which specific configuration can CVE-2026-13057 be exploited?
This vulnerability can be exploited specifically in sharded topologies when using the `$search` and `$searchMeta` aggregation stages within the server's Atlas Search integration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.