What is CVE-2026-13058?
CVE-2026-13058 allows an authenticated user with basic write privileges to abnormally terminate the `mongod` process by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across transaction command parameters, causing a fatal error. It is recommended to immediately apply the security update to protect MongoDB servers.
Azərbaycanca: CVE-2026-13058 zəifliyi autentifikasiya olunmuş, əsas yazma icazələrinə malik istifadəçiyə xüsusi hazırlanmış `transaction` əmri ilə `mongod` prosesini anormal şəkildə sonlandırmağa imkan verir. Bu, tranzaksiya əmrinin parametrlərinin validasiyasındakı uyğunsuzluqdan qaynaqlanır. MongoDB serverlərini qorumaq üçün dərhal təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
FAQ2
How does CVE-2026-13058 affect a MongoDB server?
CVE-2026-13058 allows an authenticated user with basic write privileges to abnormally terminate the `mongod` process by sending a crafted transaction command.
What is the root cause of CVE-2026-13058?
The vulnerability stems from inconsistent validation across transaction command parameters, which causes a fatal error.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.