What is CVE-2026-13071?
CVE-2026-13071 is a vulnerability where an authenticated user with read access can terminate the mongod process using certain aggregation expressions that execute server-side JavaScript due to improper memory handling during document processing. It is recommended to restrict user permissions until the affected systems are patched.
Azərbaycanca: CVE-2026-13071 MongoDB-in mongod prosesində oxuma icazəsi olan autentifikasiya olunmuş istifadəçinin server-side JavaScript işlədən aqreqasiya ifadələri vasitəsilə prosesi dayandırmasına imkan verən boşluqdur. Təsirə məruz qalan sistemlərdə memory handling qüsuru aradan qaldırılana qədər istifadəçi icazələrini məhdudlaşdırmaq tövsiyə olunur.
FAQ2
What minimum privileges must an attacker have to exploit CVE-2026-13071?
The attacker must be an authenticated user with read access to the mongod process.
What is the root cause of CVE-2026-13071 and how is it exploited?
The vulnerability is caused by improper memory handling during document processing. An authenticated user can trigger it using aggregation expressions that execute server-side JavaScript to terminate the mongod process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.