Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13073

Опубликовано: 22 июл. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.28 (исключая)

EPSS

Процентиль: 12%
0.00217
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.

CVSS3: 4.3
debian
2 месяца назад

An authenticated user with read-only privileges can cause the mongod p ...

CVSS3: 4.3
github
2 месяца назад

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.

EPSS

Процентиль: 12%
0.00217
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-617