An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with… (CVE-2026-13058)
An authenticated user with basic write privileges in MongoDB can cause the mongod process to terminate abnormally by sending a crafted transaction command missing required fields. This vulnerability arises from inconsistent validation of transaction command parameters, leading to a fatal internal error and denial of service.
AI Analysis
Technical Summary
CVE-2026-13058 is a vulnerability in MongoDB where an authenticated user with basic write privileges can trigger a denial of service by sending a specially crafted transaction command with an incomplete set of required fields. The root cause is inconsistent validation across related transaction command parameters, which causes a fatal internal invariant failure in the mongod process, resulting in abnormal termination.
Potential Impact
Successful exploitation causes the mongod process to crash, resulting in denial of service. This disrupts database availability but does not indicate data corruption or unauthorized data access based on the provided information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict write privileges to trusted users only and monitor for unusual transaction commands. No official fix or patch links are currently provided.
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with… (CVE-2026-13058)
Description
An authenticated user with basic write privileges in MongoDB can cause the mongod process to terminate abnormally by sending a crafted transaction command missing required fields. This vulnerability arises from inconsistent validation of transaction command parameters, leading to a fatal internal error and denial of service.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13058 is a vulnerability in MongoDB where an authenticated user with basic write privileges can trigger a denial of service by sending a specially crafted transaction command with an incomplete set of required fields. The root cause is inconsistent validation across related transaction command parameters, which causes a fatal internal invariant failure in the mongod process, resulting in abnormal termination.
Potential Impact
Successful exploitation causes the mongod process to crash, resulting in denial of service. This disrupts database availability but does not indicate data corruption or unauthorized data access based on the provided information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict write privileges to trusted users only and monitor for unusual transaction commands. No official fix or patch links are currently provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-538q-5r7v-2m59
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-13058"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a6150de9c2644c7f8da148f
Added to database: 07/22/2026, 23:23:10 UTC
Last enriched: 07/22/2026, 23:34:08 UTC
Last updated: 07/23/2026, 02:51:54 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.