Internal Metadata Manipulation in MongoDB Sharded Clusters
CVE-2026-13062

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13062?

A weakness exists in MongoDB that allows an authenticated user with write privileges on a Queryable Encryption-enabled collection to manipulate internal encryption metadata fields. This occurs via specially crafted write commands sent through the mongos router in a sharded cluster environment, potentially leading to corruption of encrypted query correctness and impairing data integrity. Security measures should be reviewed to protect against this risk, especially in environments utilizing sharded clusters and Queryable Encryption features.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.2.0 < 8.2.12

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.