CVE-2026-13072

HIGH

MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption

Title source: cna
STIX 2.1

Description

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0032
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (4)
MongoDB/MongoDB Server 7.0 - 7.0.39
MongoDB/MongoDB Server 8.0 - 8.0.28
MongoDB/MongoDB Server 8.2.0 - 8.2.12
MongoDB/MongoDB Server 8.3.0 - 8.3.7
Published Jul 22, 2026
Tracked Since Jul 23, 2026