Looking for the vulnerability index of Invicti's legacy products?
MongoDb Incorrect Authorization Vulnerability - CVE-2026-13060 - Vulnerability Database

MongoDb Incorrect Authorization Vulnerability - CVE-2026-13060

Medium
Reference: CVE-2026-13060
Title: MongoDb Incorrect Authorization Vulnerability
Overview:

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read due to an inconsistency in how the graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.