CVE-2026-13062
Received Received - Intake

MongoDB Queryable Encryption Metadata Corruption via Crafted Write Commands

Vulnerability report for CVE-2026-13062, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: MongoDB, Inc.

Description

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-23
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mongodb mongodb *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user with write access to modify internal encryption metadata in a Queryable Encryption-enabled MongoDB collection. The attacker can send crafted commands through the mongos router in a sharded cluster, which may corrupt encrypted query correctness and lead to data integrity issues.

Impact Analysis

If exploited, this vulnerability could result in incorrect query results for encrypted data, potentially leading to data corruption or unauthorized access. Users relying on encrypted data integrity may face reliability issues or security breaches.

Compliance Impact

This vulnerability could impact compliance by compromising data integrity and confidentiality, which are core requirements of GDPR and HIPAA. Organizations may fail to meet encryption and access control standards, risking legal penalties or loss of trust.

Mitigation Strategies

Apply the latest security patches or updates provided by MongoDB to address the issue with Queryable Encryption-enabled collections. Ensure that only authorized users have write privileges and review internal encryption metadata fields for any unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13062. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart