CVE-2026-13066 UNKNOWN

CVE-2026-13066

Published: 2026-07-22

Description

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…