CVE-2026-13058

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across related transaction command parameters, resulting in a fatal internal invariant failure and denial of service.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-127661 Vendor Advisory Issue Tracking Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-07-22 20:16

Updated : 2026-08-05 15:09


NVD link : CVE-2026-13058

Mitre link : CVE-2026-13058

CVE.ORG link : CVE-2026-13058


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-617

Reachable Assertion