PT-2026-63479 · Mongodb · Mongodb

CVE-2026-13075

·

Published

2026-07-22

·

Updated

2026-08-19

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mongod (affected versions not specified)
Description An authenticated user with the ability to run aggregation queries can cause the mongod process to be terminated by the operating system during periods of memory pressure. This issue occurs within the server's error-handling path when using the $rankFusion and $scoreFusion aggregation stages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MONGODB-2026-13075
CVE-2026-13075

Affected Products

Mongodb