
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-13075 is a Denial of Service vulnerability in MongoDB Server affecting the $rankFusion and $scoreFusion aggregation stages. An authenticated user can trigger the mongod process to be terminated by the operating system under memory pressure by exploiting a flaw in the server's error-handling path. Affected versions include MongoDB Server 8.2.0 through 8.2.11 and 8.3.0 through 8.3.6. It was published on July 22, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the server's error-handling path within the $rankFusion and $scoreFusion aggregation stages fails to properly constrain memory allocation under pressure conditions. An attacker with network access and low-privilege credentials (sufficient to run aggregation queries) can craft aggregation pipeline queries targeting these stages, causing uncontrolled memory consumption that leads the OS to terminate the mongod process via OOM (Out-of-Memory) killing. No special configuration or user interaction is required beyond the ability to execute aggregation queries. The vulnerability is tracked upstream in MongoDB's issue tracker as SERVER-128316 (GitHub Advisory, MongoDB Jira).
Successful exploitation results in a complete availability loss of the MongoDB database service, as the mongod process is forcibly terminated by the operating system. There is no impact on confidentiality or data integrity — the vulnerability is purely a Denial of Service. Any application or service dependent on the affected MongoDB instance would experience an outage until the process is restarted, and repeated exploitation could prevent sustained database availability (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.41% (0.235% per GitHub Advisory), placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the requirement for authenticated access (GitHub Advisory).
find and aggregate privileges on a database).db.version()).$rankFusion or $scoreFusion stage designed to trigger the error-handling path under memory pressure conditions./var/log/syslog or /var/log/messages) with OOM killer messages referencing the mongod process; MongoDB logs showing aggregation queries involving $rankFusion or $scoreFusion stages immediately before the crash.mongod process; repeated mongod restarts in a short time window as recorded by process supervisors (e.g., systemd, init).dmesg output referencing mongod; elevated memory usage on the MongoDB host preceding the crash.MongoDB has released patched versions addressing this vulnerability: 8.2.12 and 8.3.7. Users should upgrade to these versions as the primary remediation. As an interim workaround if patching cannot be immediately deployed, restrict aggregation query permissions to only trusted users by reviewing and tightening MongoDB role assignments. Additionally, implementing OS-level memory limits (e.g., via cgroups or ulimit) for the mongod process can reduce the impact of memory exhaustion. Monitoring for unexpected mongod process crashes and alerting on OOM events is also recommended (GitHub Advisory, MongoDB Jira).
Coverage of CVE-2026-13075 has been limited to automated vulnerability tracking platforms and security aggregators. BeyondMachines noted it as part of a broader MongoDB patch release addressing 26 vulnerabilities, including a critical memory corruption flaw. No significant independent researcher commentary or social media discussion has been identified at this time (BeyondMachines).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"