Impact
An insecure direct object reference in Mongoid’s nested attributes handling allows a user with ordinary privileges to reference a record ID that does not belong to them. When such a request is processed, the application looks up that record without enforcing the usual ownership checks, then updates and links the data to the requesting user’s own record. The result is unintended disclosure of another user’s data and unauthorized modification of sensitive information, a flaw catalogued as CWE‑639.
Affected Systems
The vulnerability exists in the Mongoid object‑document mapper supplied by MongoDB Inc. Version specifics are not disclosed in the available data; any deployment that uses Mongoid may be affected until an update is applied.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as high severity. Its EPSS score is below 1%, indicating a low probability of widespread exploitation, and it is currently not listed in the CISA KEV catalog. However, the required conditions are minimal: any authenticated user can submit a crafted nested attribute containing an arbitrary record identifier. Once this request is processed, the application will perform the forbidden update, so the vulnerability is remotely exploitable through normal application traffic.
OpenCVE Enrichment