What is CVE-2026-13076?
An authenticated user can trigger disproportionate memory consumption via a data type conversion operation in MongoDB's aggregation framework, causing the mongod process to be terminated by the OS under memory pressure. This affects system availability. Update affected versions and restrict aggregation query access for untrusted users.
Azərbaycanca: MongoDB-nin aqreqasiya çərçivəsində autentifikasiya olunmuş istifadəçi spesifik məlumat tipi çevirmə əməliyyatı ilə həddindən artıq yaddaş istehlakına səbəb olaraq əməliyyat sistemi tərəfindən mongod prosesinin sonlandırılmasına yol aça bilər. Bu, sistemin əlçatanlığını pozur. Təsirə məruz qalan versiyalar varsa, yenilənmə tətbiq edilməli və etibarsız istifadəçilərin aqreqasiya sorğuları məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: MongoDB
FAQ1
What can an authenticated attacker exploiting CVE-2026-13076 cause on a MongoDB server?
An authenticated user can trigger disproportionate memory consumption via a data type conversion operation in MongoDB's aggregation framework, causing the mongod process to be terminated by the OS under memory pressure, thus affecting system availability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.