SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13065

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

A vulnerability exists that allows users with read-only privileges to exploit the $linearFill window function operator in aggregation pipelines, leading to abnormal termination of the mongod process and causing a denial of service. This issue arises from inadequate validation of sort specifications during execution. Organizations using affected MongoDB products should prioritize patching to mitigate potential service disruptions.

CVE
CVE-2026-13065
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

Related CVEs

Other vulnerabilities affecting the same vendor(s)