
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-13077 is an out-of-bounds heap read vulnerability in MongoDB Server's BSON CodeWScope element accessors that allows an authenticated attacker to trigger a server crash or disclose adjacent heap memory contents via a crafted aggregation pipeline. It was published on July 22, 2026, and affects MongoDB Server versions 7.0 before 7.0.39, 8.0 before 8.0.28, 8.2.0 before 8.2.12, and 8.3.0 before 8.3.7. The vulnerability carries a CVSS v4 base score of 7.1 (High) (GitHub Advisory).
The root cause is a missing bounds check (CWE-125: Out-of-bounds Read) in the BSON CodeWScope element accessors within MongoDB's BSONColumn decompression logic. An authenticated attacker can craft malformed BSONColumn data containing a CodeWScope element that bypasses wire-level BSON validation; when the forged element is decompressed, an unchecked size value is used in pointer arithmetic, resulting in a read beyond the intended heap buffer. This attack vector is network-accessible, requires low privileges (authenticated user), and no user interaction, making it straightforward to trigger once access to the database is obtained (GitHub Advisory, MongoDB Jira).
Successful exploitation can result in two distinct outcomes: a denial-of-service condition via server crash, or limited disclosure of adjacent heap memory contents, which may expose sensitive in-memory data such as query results, credentials, or other database contents. The availability impact is rated High, while confidentiality impact is Low, and there is no integrity impact. The vulnerability is scoped to the vulnerable MongoDB Server instance itself, with no direct lateral movement capability, but heap memory disclosure could potentially aid further attacks (GitHub Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.24% (15th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" at this time.
$group, $project, or similar stage that processes BSONColumn data), targeting an affected version (7.0 < 7.0.39, 8.0 < 8.0.28, 8.2.0 < 8.2.12, 8.3.0 < 8.3.7).mongod process restarts; error log entries referencing BSONColumn decompression failures or memory access violations; aggregation pipeline errors involving CodeWScope element processing.mongod process (SIGSEGV or similar signals); core dump files generated in the MongoDB working directory following aggregation operations.core, core.mongod.<pid>) in the MongoDB data or working directory following unexpected crashes.MongoDB has released patched versions addressing this vulnerability: upgrade to MongoDB Server 7.0.39, 8.0.28, 8.2.12, or 8.3.7 as appropriate for your release track (MongoDB Jira). As a network-level workaround, restrict access to MongoDB instances to trusted clients only using firewall rules or MongoDB's built-in authentication and network binding controls. Monitor for unexpected server crashes or memory access errors as an interim detection measure. Upgrading to a patched version is the recommended and definitive remediation.
Security coverage noted MongoDB patching 26 vulnerabilities in a batch release that included this flaw alongside other memory-related issues (beyondmachines.net). Tenable added detection support via Nessus plugins (330171 and 331215) shortly after disclosure (Tenable). No significant social media controversy or notable individual researcher commentary has been observed for this specific CVE.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"