CVE-2026-13069
MongoDB MongoDB Server
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.
- CVSS
- 7.1
- EPSS
- 0.16% 5.29% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.23