← Back to CVE List
CVE-2026-13077NVD
Vulnerability Summary
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONColumn data containing a CodeWScope element, bypassing wire-level BSON validation. When the forged element is decompressed, the unchecked size value is used in pointer arithmetic, causing either a server crash or disclosure of adjacent heap memory contents.
CVSS v4.0 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- MongoDB MongoDB Server >= 7.0 and < 7.0.39
- MongoDB MongoDB Server >= 8.0 and < 8.0.28
- MongoDB MongoDB Server >= 8.2.0 and < 8.2.12
- MongoDB MongoDB Server >= 8.3.0 and < 8.3.7
- MongoDB MongoDB Server 7.0.39
- MongoDB MongoDB Server 8.0.28
- MongoDB MongoDB Server 8.2.12
- MongoDB MongoDB Server 8.3.7