CVE-2026-13061 | MongoDB Server up to 7.0.38/8.0.27/8.3.6 Aggregation listSessions privileges management
A vulnerability labeled as problematic has been found in MongoDB Server up to 7.0.38/8.0.27/8.3.6. This affects the function listSessions of the component Aggregation. Such manipulation of the argument listSessions leads to improper privilege management.
This vulnerability is documented as CVE-2026-13061. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More