SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13069

MEDIUM · CVSS 6.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB servers are vulnerable to excessive CPU consumption and potential out-of-memory conditions due to crafted Queryable Encryption find payloads that exploit an unvalidated field in internal computation loops. This resource exhaustion can degrade the availability of the database for other operations, impacting overall system performance. Organizations using MongoDB should prioritize addressing this vulnerability to maintain service reliability and prevent denial-of-service scenarios.

CVE
CVE-2026-13069
Severity
MEDIUM
CVSS
6.5
EPSS
0.17%
MongoDB

Original NVD Description

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)