Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-13072: MongoDB Compute Mode Memory Corruption in External Data
CVE-2026-13072 · published 2 months ago
Summary
MongoDB's compute mode can be vulnerable to memory corruption if it processes invalid data from external sources. This is a risk if you're using compute mode, but it's not a default setting and requires explicit enablement. To stay safe, ensure you're only using compute mode when necessary and validate any external data being processed.
What to do
- Update mongodb mongodb server to version 7.0.39 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | mongodb | mongodb server | < 7.0.39 |
| Ubuntu:Pro:14.04:LTS | canonical | mongodb | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | mongodb | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | mongodb | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | mongodb | All versions |
Original advisory text
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potenti...
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.
References
- https://jira.mongodb.org/browse/SERVER-128494
- https://www.cve.org/CVERecord?id=CVE-2026-13072 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-13072 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-13072 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13072... Vendor Advisory
Severity
9.2
Critical
CVSS 3.1: 8.1 (MITRE)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published22 Jul 2026
Updated27 Sep 2026
First seen23 Jul 2026
Sources
CVE-2026-13072 · OSV
CVE-2026-13072 · NVD
CVE-2026-13072 · MITRE
UBUNTU-CVE-2026-13072 · OSV
Track software like this
Free during beta