What is CVE-2026-13066?
CVE-2026-13066 is an information disclosure vulnerability in MongoDB where improper handling of DBPointer objects during BSON serialization in the server-side JavaScript engine can leak internal process memory to the client. This primarily affects deployments that utilize server-side JavaScript. Affected users should apply the security patch provided by MongoDB.
Azərbaycanca: CVE-2026-13066 MongoDB-in server-side JavaScript mühərrikində BSON serializasiyası zamanı DBPointer obyektlərinin düzgün idarə olunmaması səbəbindən daxili proses yaddaş məzmununun müştəriyə qaytarılan məlumatlara daxil edilməsi ilə məxfilik pozuntusuna səbəb olur. Bu qüsur xüsusilə server-side JavaScript istifadə edən deployment-lərə təsir edir. Təsirə məruz qalan istifadəçilərə MongoDB tərəfindən təqdim olunan təhlükəsizlik yamasını tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: MongoDB
FAQ2
What functional area of MongoDB does CVE-2026-13066 affect?
This vulnerability affects the improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine.
Which deployments are primarily affected by CVE-2026-13066?
This flaw primarily affects MongoDB deployments that utilize server-side JavaScript.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.