MongoDb Incorrect Authorization Vulnerability - CVE-2026-13061
An authenticated user may be able to view session metadata belonging to other users on the system through the listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges and includes active session identifiers associated usernames and activity timestamps.