What is CVE-2026-13073?
CVE-2026-13073 is a vulnerability in MongoDB. An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command. This results in a denial of service for all connected clients until the process is restarted.
Azərbaycanca: CVE-2026-13073 MongoDB-də aşkar edilmiş zəiflikdir. Yalnız oxuma hüququna malik autentifikasiya olunmuş istifadəçi, xüsusi hazırlanmış `aggregation` sorğusu göndərərək `mongod` prosesini qeyri-normal şəkildə dayandıra bilər. Bu, proses yenidən başladılana qədər bütün bağlı müştərilər üçün xidmət dayanmasına (denial of service) səbəb olur.
FAQ2
What level of privileges does an attacker need to exploit CVE-2026-13073?
The attacker must be an authenticated user, but having only read-only privileges is sufficient.
What is the impact of successfully exploiting CVE-2026-13073?
It causes the mongod process to terminate abnormally, resulting in a denial of service until the process is restarted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.