What is CVE-2026-13072?
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption. This may lead to process termination or other unintended behavior. Affected non-default configurations should disable compute mode or apply the official patch.
Azərbaycanca: CVE-2026-13072 MongoDB-in standolone 'compute mode' aktiv olduqda, agreqasiya boru xəttində xarici BSON dataların zəif yoxlanması səbəbindən yaddaş korrupsiyasına yol açır. Bu, prosesin sonlanmasına və ya gözlənilməz davranışlara səbəb ola bilər. Qeyri-standart konfiqurasiyaya təsir etdiyi üçün, təsirlənmiş sistemlərdə 'compute mode' deaktiv edilməli və ya rəsmi patch tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
In which MongoDB mode does CVE-2026-13072 cause memory corruption when enabled?
This vulnerability occurs only when 'compute mode' is enabled on a standalone mongod instance.
What is the recommended mitigation for CVE-2026-13072?
Affected non-default configurations should disable compute mode.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.