CyberRota Analysis
AI-GeneratedAn authenticated user with limited read privileges may exploit a flaw in the $graphLookup aggregation stage, allowing unauthorized access to documents in collections they should not be able to view. This vulnerability primarily affects scenarios involving collections referenced in existing view pipeline definitions. Organizations utilizing this aggregation feature should prioritize remediation to prevent potential data exposure.
Original NVD Description
An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.
Related CVEs
Other vulnerabilities affecting the same vendor(s)