CVE-2026-13075 | MongoDB Server up to 8.2.11/8.3.6 Aggregation rankFusion/scoreFusion resource consumption
A vulnerability described as critical has been identified in MongoDB Server up to 8.2.11/8.3.6. The impacted element is an unknown function of the component Aggregation. The manipulation of the argument rankFusion/scoreFusion results in resource consumption.
This vulnerability is reported as CVE-2026-13075. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More