What is CVE-2026-13062?
CVE-2026-13062 is a vulnerability affecting MongoDB's Queryable Encryption feature. An authenticated user with write privileges may corrupt data by sending crafted write commands via the `mongos` router on a sharded cluster, modifying internal encryption metadata fields intended to be server-controlled. Updating to the latest patched MongoDB version is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-13062 MongoDB-in Queryable Encryption funksiyasına təsir edən boşluqdur. Yazma icazəsi olan autentifikasiya olunmuş istifadəçi, şardlaşdırılmış klasterdə `mongos` marşrutlaşdırıcısı vasitəsilə xüsusi hazırlanmış əmrlər göndərərək, server tərəfindən idarə olunan daxili şifrələmə metadata sahələrini dəyişdirə bilər. Bu, məlumatların pozulmasına səbəb ola bilər, ona görə də MongoDB versiyasını ən son təhlükəsizlik yaması ilə yeniləmək tövsiyə olunur.
FAQ2
Which specific feature of MongoDB is affected by the CVE-2026-13062 vulnerability?
The CVE-2026-13062 vulnerability affects MongoDB's Queryable Encryption feature.
What privileges does an attacker need to exploit the CVE-2026-13062 vulnerability?
The attacker must be an authenticated user with write privileges, sending commands via the `mongos` router on a sharded cluster.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.