Security Advisory

CVE-2026-13069

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-22 19:15:38
Last updated 2026-07-23 14:21:57
Assigner mongodb
CVSS score 7.1
State PUBLISHED

Description

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.