Denial of Service Vulnerability in MongoDB by Authenticated Users
CVE-2026-13073

5.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13073?

A vulnerability exists in MongoDB Server, where an authenticated user with read-only privileges can exploit a flaw in the aggregation command processing. By sending a specially crafted command, this user can cause the mongod process to terminate unexpectedly, resulting in a denial of service for all connected clients. The issue is rooted in an inconsistency during internal engine selection related to specific aggregation options, requiring a restart of the process to restore service. This presents significant availability risks for systems relying on MongoDB.

Affected Version(s)

MongoDB Server 8.0 < 8.0.28

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.