Description
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This may result in unintended disclosure and unauthorized modification of data belonging to other users of the application.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and disclosure
Action: Immediate Patch
AI Analysis

Impact

An insecure direct object reference in Mongoid’s nested attributes handling allows a user with ordinary privileges to reference a record ID that does not belong to them. When such a request is processed, the application looks up that record without enforcing the usual ownership checks, then updates and links the data to the requesting user’s own record. The result is unintended disclosure of another user’s data and unauthorized modification of sensitive information, a flaw catalogued as CWE‑639.

Affected Systems

The vulnerability exists in the Mongoid object‑document mapper supplied by MongoDB Inc. Version specifics are not disclosed in the available data; any deployment that uses Mongoid may be affected until an update is applied.

Risk and Exploitability

The CVSS score of 8.6 classifies this issue as high severity. Its EPSS score is below 1%, indicating a low probability of widespread exploitation, and it is currently not listed in the CISA KEV catalog. However, the required conditions are minimal: any authenticated user can submit a crafted nested attribute containing an arbitrary record identifier. Once this request is processed, the application will perform the forbidden update, so the vulnerability is remotely exploitable through normal application traffic.

Generated by OpenCVE AI on September 19, 2026 at 16:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Mongoid patch version that addresses the nested attributes ID validation flaw
  • Verify that the application validates ownership of records before performing updates and enforce strict access controls in the data access layer
  • Disable or restrict the use of nested attributes unless absolutely necessary, and implement custom middleware to reject unauthorized ID references

Generated by OpenCVE AI on September 19, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This may result in unintended disclosure and unauthorized modification of data belonging to other users of the application.
Title Cross-principal document update, theft, and deletion via unvalidated id in nested attributes
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:46:56.818Z

Reserved: 2026-09-18T16:51:38.102Z

Link: CVE-2026-93758

cve-icon Vulnrichment

Updated: 2026-09-21T18:46:52.997Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T17:17:07.580

Modified: 2026-09-25T14:12:35.223

Link: CVE-2026-93758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key