Unrated severityNVD Advisory· Published Jul 22, 2026· Updated Jul 23, 2026
MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse
CVE-2026-13068
Description
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.