High severity8.1NVD Advisory· Published Jul 22, 2026· Updated Aug 5, 2026
CVE-2026-13059
CVE-2026-13059
Description
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-128433nvdVendor AdvisoryIssue Tracking
News mentions
0No linked articles in our index yet.