SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13075

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Authenticated users can exploit a vulnerability in the aggregation stages of the server, specifically through $rankFusion and $scoreFusion, leading to the termination of the mongod process under memory pressure. This could result in service disruption and potential data unavailability. Organizations utilizing this database should prioritize addressing this issue to mitigate risks associated with unauthorized query execution.

CVE
CVE-2026-13075
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and requires the ability to run aggregation queries.

Related CVEs

Other vulnerabilities affecting the same vendor(s)