SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13072

HIGH · CVSS 8.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

A standalone mongod instance with compute mode enabled is vulnerable due to inadequate validation of externally sourced BSON data during aggregation pipeline processing, which can lead to memory corruption and potential process termination. Organizations using this configuration should prioritize remediation efforts, as the risk of unintended behavior could compromise system stability and data integrity.

CVE
CVE-2026-13072
Severity
HIGH
CVSS
8.1
EPSS
0.32%

Original NVD Description

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

Related CVEs

Other vulnerabilities affecting the same vendor(s)