Impact
An authenticated user is able to view the session metadata of other data includes active session identifiers, usernames, and activity timestamps, information normally restricted permits user enumeration and could facilitate session hijacking or other credential‑based attacks. The weakness is an improper access control error identified as CWE‑863.
Affected Systems
The vulnerability applies to MongoDB Server applications. No specific version information is provided in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must first be authenticated to the MongoDB instance and then issue a $listSessions query, which is feasible for any user with normal privileges on the system.
OpenCVE Enrichment