CVE-2026-13062: MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13062?
The severity of CVE-2026-13062 is medium, rated at 6.5.
How do I fix CVE-2026-13062?
To fix CVE-2026-13062, ensure that only trusted users have write access to Queryable Encryption-enabled collections and apply security patches as they become available.
What are the potential risks of CVE-2026-13062?
Exploitation of CVE-2026-13062 can lead to the corruption of internal encryption metadata fields, potentially compromising data integrity.
Who is affected by CVE-2026-13062?
Users of MongoDB mongos who have enabled Queryable Encryption on sharded clusters and granted write privileges are affected by CVE-2026-13062.
What is the impact of CVE-2026-13062 on data security?
CVE-2026-13062 can impact data security by allowing authenticated users to manipulate encryption metadata, which can lead to data integrity issues.