SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13066

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB's server-side JavaScript engine is vulnerable due to improper handling of DBPointer objects during BSON serialization, which may inadvertently expose internal process memory contents to clients. This information disclosure risk primarily affects deployments utilizing server-side JavaScript. Organizations using MongoDB with Java should prioritize addressing this vulnerability to mitigate potential data leaks.

CVE
CVE-2026-13066
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%
MongoDB Java

Original NVD Description

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.

Related CVEs

Other vulnerabilities affecting the same vendor(s)