CVE-2026-13076 HIGH

CVE-2026-13076: Aggregation Framework Memory Exhaustion Leading to Process Termination

Vendor Mongodb
Product MongoDB Server
Weakness CWE-770 · Uncontrolled resource consumption
Published July 22, 2026
Last update July 23, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

Key dates

02Disclosure timeline

July 22, 2026 CVE published
July 23, 2026 Record updated