Vulnerability Description
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 7.0.0, < 7.0.39 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-127831Vendor AdvisoryIssue Tracking
FAQ
What is CVE-2026-13062?
CVE-2026-13062 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending...
How severe is CVE-2026-13062?
CVE-2026-13062 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13062?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.