Description
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Mongoid library, which does not neutralize string‑typed query criteria. When an unauthenticated attacker supplies such a criterion, it is forwarded directly to MongoDB as a server‑side JavaScript expression. The database engine evaluates the injected code, enabling the attacker to execute arbitrary code on the database. This can lead to disclosure of sensitive field values, covert selection of documents that the application may subsequently modify, and a measurable degradation of database performance. The flaw is a classic code‑injection weakness (CWE‑94).

Affected Systems

Any deployment that uses MongoDB Inc.’s Mongoid as the ODM is potentially impacted. The advisory does not list specific version ranges, so any installation of Mongoid that permits string query criteria is at risk until a patched version is applied.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity vulnerability. The EPSS score of less than 1% indicates that current exploitation attempts are unlikely to be widespread, though the vulnerability remains exploitable. It is not recorded in the CISA KEV catalog. The attack can be performed remotely by inserting malicious strings into application inputs that are passed as query criteria, and no authentication is required to trigger the code evaluation.

Generated by OpenCVE AI on September 19, 2026 at 16:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Mongoid version that escapes or rejects string query criteria before passing to MongoDB.
  • Implement input validation to reject or sanitize any string that could be interpreted as JavaScript, ensuring strict operator enforcement.
  • Disable or restrict server‑side JavaScript execution in the MongoDB configuration if the application does not require it, to reduce the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.
Title Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:15:19.296Z

Reserved: 2026-09-18T16:51:38.630Z

Link: CVE-2026-93759

cve-icon Vulnrichment

Updated: 2026-09-21T18:15:15.352Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T18:18:34.640

Modified: 2026-09-24T16:19:37.887

Link: CVE-2026-93759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')