CVE-2026-13073: MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13073?
The severity of CVE-2026-13073 is medium with a score of 4.3.
How can CVE-2026-13073 affect my MongoDB deployment?
CVE-2026-13073 can lead to process termination of the MongoDB server, causing denial of service for connected clients.
Who is affected by CVE-2026-13073?
Authenticated users with read-only privileges can exploit CVE-2026-13073.
What happens when CVE-2026-13073 is exploited?
Exploiting CVE-2026-13073 results in an abnormal termination of the mongod process.
How do I fix CVE-2026-13073?
The immediate fix for CVE-2026-13073 involves restarting the mongod process to restore service.