Server Crash Vulnerability in MongoDB by MongoDB, Inc.
CVE-2026-13055

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13055?

An authenticated user can exploit a flaw in the aggregation expression $_internalIndexKey in MongoDB, leading to a crash of the MongoDB server. This occurs when the expression fails to properly handle compound wildcard index specifications, causing an internal consistency check to trigger an unexpected server abort. To exploit this vulnerability, the user must be able to execute an aggregation pipeline, making it critical to ensure proper validation and handling of input in the server's processing logic.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.2.0 < 8.2.12

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.