CVE-2026-13073

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-128512 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-22 20:16

Updated : 2026-08-18 16:16


NVD link : CVE-2026-13073

Mitre link : CVE-2026-13073

CVE.ORG link : CVE-2026-13073


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-617

Reachable Assertion