Security Advisory
CVE-2026-13062
6.5
MEDIUM
Vulnerability Description
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.
Published Date
July 22, 2026
Official Source
NIST NVD Advisory