CVE-2026-13060 | MongoDB Server up to 7.0.38/8.0.27/8.2.11/8.3.6 GraphLookup Aggregation Stage $graphLookup improper authorization

SecurityVulns

A vulnerability was found in MongoDB Server up to 7.0.38/8.0.27/8.2.11/8.3.6. It has been declared as problematic. This impacts the function $graphLookup of the component GraphLookup Aggregation Stage. Executing a manipulation can lead to improper authorization.

This vulnerability is tracked as CVE-2026-13060. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More