Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-13062

Опубликовано: 22 июл. 2026
Источник: debian
EPSS Низкий

Описание

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongodbremovedpackage

Примечания

  • https://jira.mongodb.org/browse/SERVER-127831

EPSS

Процентиль: 8%
0.00188
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

CVSS3: 6.5
nvd
около 1 месяца назад

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

CVSS3: 6.5
github
около 1 месяца назад

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

EPSS

Процентиль: 8%
0.00188
Низкий