What is CVE-2026-13060?
CVE-2026-13060 is a vulnerability in MongoDB where an authenticated user with limited read privileges can access documents from unauthorized collections. This occurs due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization versus execution. Users are advised to update MongoDB and review their role configurations.
Azərbaycanca: CVE-2026-13060 MongoDB-də aşkarlanmış zəiflikdir. Bu, autentifikasiya olunmuş, lakin məhdud oxuma hüquqları olan istifadəçinin $graphLookup aqreqasiya mərhələsinin avtorizasiya zamanı düzgün yoxlanılmaması səbəbindən icazəsiz kolleksiyalardakı sənədlərə baxa bilməsinə imkan verir. İstifadəçilərə MongoDB versiyalarını yeniləmələri və rolları diqqətlə nəzərdən keçirmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Who can exploit CVE-2026-13060?
This vulnerability can be exploited by authenticated users with limited read privileges.
What is the root cause of CVE-2026-13060?
The root cause is an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization versus execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.