SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13071

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Authenticated users with read access to Java-based applications are vulnerable to a denial-of-service attack that can terminate the mongod process by exploiting specific aggregation expressions that execute server-side JavaScript. This vulnerability arises from improper memory handling during document processing, potentially disrupting service availability. Organizations utilizing affected Java applications should prioritize this issue to mitigate the risk of service interruptions.

CVE
CVE-2026-13071
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
Java

Original NVD Description

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)