What is CVE-2026-13077?
A missing bounds check in BSON CodeWScope element accessors allows an authenticated attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline containing a malformed BSONColumn with a CodeWScope element, affecting MongoDB environments. Update MongoDB to the latest patched version immediately to mitigate this vulnerability.
Azərbaycanca: BSON CodeWScope element girişlərində yoxlanılmayan sərhəd səbəbindən, autentifikasiya olunmuş istifadəçi xüsusi hazırlanmış aggregation pipeline vasitəsilə heap-də out-of-bounds oxuma (read) zəifliyini işə sala bilər. Bu, MongoDB mühitinə təsir edir. İstismarın qarşısını almaq üçün dərhal MongoDB versiyasını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Through which operation can CVE-2026-13077 be exploited in MongoDB?
The vulnerability can be exploited by an authenticated attacker via a crafted aggregation pipeline.
What type of memory vulnerability does CVE-2026-13077 cause?
The vulnerability causes an out-of-bounds heap read due to a missing bounds check in BSON CodeWScope element accessors.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.