Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-13062

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.0%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-13062


Contact Us

Shodan ® - All rights reserved