Remote Code Execution Vulnerability in MongoDB Server
CVE-2026-13074
6.9MEDIUM
What is CVE-2026-13074?
A vulnerability exists in MongoDB Server that allows unauthenticated remote clients to trigger excessive CPU consumption. By sending a specific combination of parameters to the awaitable hello command in exhaust mode, the server may enter a response loop that circumvents normal throttling mechanisms. This condition can lead to degraded server performance and availability, posing a significant risk to applications relying on MongoDB for their operations.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12