LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-13072

mongodb · mongodb

Published
CVSS8.1
Severityhigh
WeaknessCWE-122
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-13072

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-13072.