What is CVE-2026-13055?
CVE-2026-13055 is a critical vulnerability in MongoDB server (mongod) allowing any authenticated user to crash the server using the `$_internalIndexKey` aggregation expression. The flaw is triggered by improper handling of compound wildcard index specifications. Upgrading MongoDB to the latest version is required to mitigate this issue.
Azərbaycanca: CVE-2026-13055 MongoDB server (mongod) üçün kritik zəiflikdir. İdentifikasiya olunmuş istənilən istifadəçi `$_internalIndexKey` aqreqasiya ifadəsi vasitəsilə serveri çökdürə bilər. Sistem administratorları MongoDB-ni ən son versiyaya yeniləməli və bu ifadənin istifadəsini məhdudlaşdırmalıdır.
Related CVEs
link basis: shared vendor: MongoDB
FAQ2
How does CVE-2026-13055 affect the MongoDB server?
The vulnerability allows any authenticated user to crash the mongod server using the `$_internalIndexKey` aggregation expression.
What action should be taken to mitigate CVE-2026-13055?
System administrators must upgrade MongoDB to the latest version and restrict usage of the `$_internalIndexKey` expression.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.