SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13062

MEDIUM · CVSS 6.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Authenticated users with write privileges on a Queryable Encryption-enabled collection may exploit this vulnerability to manipulate internal encryption metadata fields, potentially leading to corrupted encrypted query results. Organizations utilizing sharded clusters with this feature should prioritize addressing this issue to safeguard data integrity and prevent unauthorized data manipulation.

CVE
CVE-2026-13062
Severity
MEDIUM
CVSS
6.5
EPSS
0.11%

Original NVD Description

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

Related CVEs

Other vulnerabilities affecting the same vendor(s)