CyberRota
← Ana sayfaya dön

CVE-2026-13055

MEDIUM · CVSS 6.5

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-22T20:16:43.220 · Çekilme zamanı: 2026-07-23T06:10:54.994667+00:00

CyberRota Yorumu

MongoDB kullanan sistemleri etkileyebilir. Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-13055
Severity
MEDIUM
CVSS
6.5
EPSS
Yok
MongoDB

Orijinal NVD Açıklaması

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an aggregation pipeline.