Memory Consumption Vulnerability in MongoDB Affected by Specific Operations
CVE-2026-13076

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13076?

An authenticated user can exploit a vulnerability in MongoDB that allows them to induce excessive memory consumption during a specific data type conversion operation within the aggregation framework. This behavior can lead the operating system to terminate the {{mongod}} process when the server is under memory pressure. To exploit this vulnerability, the user must have write access to the database and the capability to execute aggregation queries. Understanding the implications of this vulnerability is crucial for maintaining the stability and performance of MongoDB deployments.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.