SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13076

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB is vulnerable to a denial-of-service condition where an authenticated user can terminate the {{mongod}} process under memory pressure by executing a specific data type conversion within the aggregation framework. This issue arises from excessive memory consumption during the operation, necessitating write access and the ability to run aggregation queries. Database administrators and security teams should prioritize this vulnerability to mitigate potential disruptions in service.

CVE
CVE-2026-13076
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%
MongoDB

Original NVD Description

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

Related CVEs

Other vulnerabilities affecting the same vendor(s)