Description
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-127831 |
|
History
Wed, 22 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness. | |
| Title | MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters | |
| Weaknesses | CWE-441 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-07-22T19:19:01.472Z
Reserved: 2026-06-23T18:00:05.239Z
Link: CVE-2026-13062
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')