What is CVE-2026-13075?
CVE-2026-13075 is a vulnerability affecting MongoDB's mongod process. An authenticated user can trigger a denial of service by causing the process to terminate under memory pressure using the $rankFusion and $scoreFusion aggregation stages, due to an issue in the error-handling path. Restrict aggregation query execution from untrusted users until a security patch is applied.
Azərbaycanca: CVE-2026-13075 MongoDB-in mongod prosesinə təsir edən zəiflikdir. Autentifikasiya olunmuş istifadəçi $rankFusion və $scoreFusion aqreqasiya mərhələlərini istifadə edərək yaddaş təzyiqi altında səhv idarəetmə nəticəsində prosesi çökdürə bilər. Təhlükəsizlik patchi tətbiq edilənə qədər etibarlı olmayan istifadəçilərin aqreqasiya sorğuları icra etməsi məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which MongoDB component does CVE-2026-13075 affect?
CVE-2026-13075 affects the MongoDB mongod process.
Is authentication required to exploit CVE-2026-13075?
Yes, the attacker must be an authenticated user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.