What is CVE-2026-13061?
CVE-2026-13061: An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges and includes active session identifiers and associated usernames. Applying the latest security patches is recommended to mitigate this vulnerability.
Azərbaycanca: CVE-2026-13061: Autentifikasiya olunmuş istifadəçi $listSessions aqreqasiya mərhələsi vasitəsilə digər istifadəçilərin sessiya metadatasına baxa bilər. Bu, adətən yalnız klaster səviyyəsində inzibati hüquqlara malik istifadəçilərə məxsus məlumatların (aktiv sessiya identifikatorları, istifadəçi adları) sızmasına səbəb olur. Bu boşluğu aradan qaldırmaq üçün məhsulun ən son təhlükəsizlik yamalarının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Who can exploit CVE-2026-13061?
Any authenticated user can exploit CVE-2026-13061.
What kind of data can be leaked through CVE-2026-13061?
This vulnerability can leak active session identifiers and associated usernames, which is normally restricted to users with cluster-level administrative privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.