MongoDb Improper Input Validation Vulnerability - CVE-2026-13057
An issue in the servers Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies the search and searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded search planning. Due to insufficient input validation an authenticated client can supply these fields directly.