Denial of Service Issue in MongoDB - Authenticated User Vulnerability
CVE-2026-13058
7.1HIGH
What is CVE-2026-13058?
An authenticated user with basic write privileges can exploit a flaw in MongoDB by sending a carefully crafted transaction command that lacks necessary fields. This inconsistency in the validation of transaction parameters causes the mongod process to terminate unexpectedly, leading to a denial of service condition. Organizations utilizing MongoDB are advised to monitor their systems closely and apply relevant patches to mitigate this vulnerability.
Affected Version(s)
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12
MongoDB Server 8.3.0 < 8.3.7