CVE-2026-13072
critical · 9.2When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.
9.2
CVSS
0.4%
EPSS (exploit prob.)
34th
EPSS percentile
2026-07-22
Published
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-122
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mongodb | mongodb | >= 7.0.0, < 7.0.39 |
| mongodb | mongodb | >= 8.0.0, < 8.0.28 |
| mongodb | mongodb | >= 8.2.0, < 8.2.12 |
| mongodb | mongodb | >= 8.3.0, < 8.3.7 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-13072