SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13063

MEDIUM · CVSS 4.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB is vulnerable to an out-of-memory condition triggered by authenticated users with standard read/write privileges who send specially crafted aggregation commands. This flaw arises from insufficient validation of payload-supplied values in the libmongocrypt library, potentially leading to process termination. Organizations using MongoDB should prioritize addressing this vulnerability to prevent service disruptions caused by malicious or unintentional exploitation.

CVE
CVE-2026-13063
Severity
MEDIUM
CVSS
4.3
EPSS
0.23%
MongoDB

Original NVD Description

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)