An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-128512 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-22 20:16
Updated : 2026-08-18 16:16
NVD link : CVE-2026-13073
Mitre link : CVE-2026-13073
CVE.ORG link : CVE-2026-13073
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-617
Reachable Assertion
