What is CVE-2026-13069?
CVE-2026-13069 is a vulnerability in MongoDB server. An authenticated user can cause excessive CPU consumption or out-of-memory conditions by sending a crafted Queryable Encryption find payload, leading to resource exhaustion and degraded availability.
Azərbaycanca: CVE-2026-13069 MongoDB server zəifliyidir. Autentifikasiya olunmuş istifadəçi xüsusi hazırlanmış Queryable Encryption find sorğusu göndərərək serverdə həddindən artıq CPU istehlakına və ya yaddaş tükənməsinə səbəb ola bilər, bu da əlçatanlığı aşağı salır.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: MongoDB
FAQ2
Does exploiting CVE-2026-13069 require the attacker to be authenticated?
Yes, exploiting this vulnerability requires the attacker to be an authenticated user on the MongoDB server. They can then send a crafted Queryable Encryption find payload to cause resource exhaustion.
Which aspect of the MongoDB server does CVE-2026-13069 affect?
This vulnerability affects availability. A crafted Queryable Encryption find payload can cause excessive CPU consumption or out-of-memory conditions, degrading the server's service quality.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.