CVE-2026-13076

MEDIUM

MongoDB Server - Aggregation Framework Memory Exhaustion Leading to Process Termination

Title source: rule
STIX 2.1

Description

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (1)
MongoDB/MongoDB Server 8.3.0 - 8.3.7
Published Jul 22, 2026
Tracked Since Jul 23, 2026