
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-13076 is a Denial of Service vulnerability in MongoDB Server's aggregation framework that allows an authenticated user to cause the mongod process to be terminated by the operating system under memory pressure. The vulnerability affects MongoDB Server versions 8.3.0 through 8.3.6 (fixed in 8.3.7). It was published on July 22, 2026, and is classified as High severity with a CVSS v4.0 base score of 7.1 and a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where a specific data type conversion operation within MongoDB's aggregation framework consumes disproportionate amounts of memory without adequate resource constraints. An authenticated attacker with both write access to the database and the ability to execute aggregation queries can trigger this condition over the network (no local access required, no user interaction needed). The vulnerability is tracked upstream in MongoDB's issue tracker as SERVER-128584 (GitHub Advisory, MongoDB Jira).
Successful exploitation results in the mongod process being forcibly terminated by the operating system's out-of-memory (OOM) killer, causing a complete loss of database availability. There is no impact on confidentiality or data integrity, but the crash disrupts all database operations and connected applications until the service is restarted. In environments without automatic restart mechanisms or high-availability configurations, this could result in extended service outages (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.41%, indicating a low near-term probability of exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with write privileges and aggregation query execution rights, which limits the attacker pool but does not eliminate insider or compromised-credential threat scenarios.
readWrite or higher privileges).mongosh or a driver.mongod process to consume excessive memory.mongod process, resulting in a denial of service for all connected clients (GitHub Advisory, MongoDB Jira).mongod process termination entries in system logs (e.g., Linux dmesg or /var/log/syslog) showing OOM killer events targeting the mongod process; MongoDB logs showing abrupt shutdown without a clean shutdown message.mongod process followed by automatic restart (if configured); repeated OOM kill events in a short timeframe.mongod crashes; repeated connections from the same source around the time of crashes.mongod process visible in system monitoring tools (e.g., top, htop, Prometheus metrics) immediately before termination.MongoDB has released version 8.3.7 to address this vulnerability; upgrading to this version is the recommended remediation (GitHub Advisory, MongoDB Jira). As interim workarounds, administrators should restrict aggregation query execution and database write access to only trusted and necessary users, applying the principle of least privilege. Additionally, implementing OS-level memory limits for the mongod process, enabling MongoDB's memory usage monitoring, and configuring automatic service restart can reduce the impact of exploitation.
Beyond Machines noted this CVE as part of a broader MongoDB patch release addressing 26 vulnerabilities, including a critical memory corruption flaw, highlighting the significance of the July 2026 MongoDB security update cycle. Tenable published detection plugins (Nessus plugin 330149 and 331217) to identify vulnerable MongoDB instances. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking coverage.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"