Internal Metadata Manipulation in MongoDB Sharded Clusters
CVE-2026-13062
7.1HIGH
What is CVE-2026-13062?
A weakness exists in MongoDB that allows an authenticated user with write privileges on a Queryable Encryption-enabled collection to manipulate internal encryption metadata fields. This occurs via specially crafted write commands sent through the mongos router in a sharded cluster environment, potentially leading to corruption of encrypted query correctness and impairing data integrity. Security measures should be reviewed to protect against this risk, especially in environments utilizing sharded clusters and Queryable Encryption features.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12