SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13055

MEDIUM · CVSS 6.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Authenticated users of MongoDB are vulnerable to a denial-of-service condition due to the `$_internalIndexKey` aggregation expression, which can crash the server when processing compound wildcard index specifications. This vulnerability can be exploited by any user with the ability to execute aggregation pipelines, potentially disrupting service availability. Organizations using MongoDB should prioritize remediation to prevent potential service interruptions.

CVE
CVE-2026-13055
Severity
MEDIUM
CVSS
6.5
EPSS
0.28%
MongoDB

Original NVD Description

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an aggregation pipeline.

Related CVEs

Other vulnerabilities affecting the same vendor(s)