Description
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.
Published: 2026-09-18
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential data disclosure and database performance impact
Action: Immediate Patch
AI Analysis

Impact

Mongoid does not filter query operators that come from externally supplied filter data. When an application forwards such data to Mongoid’s query builder, an unauthenticated party can inject operators that execute JavaScript code within the database. This can expose stored field values to the attacker and degrade database performance by running custom scripts. The weakness is a classic NoSQL injection flaw classified as CWE‑943.

Affected Systems

The vulnerability affects MongoDB Inc.’s Mongoid component. No specific version range is listed in the CNA data; affected builds are those that use the default, unsafe operator guard behavior of Mongoid. Users should verify whether their Mongoid installation is using the default configuration and whether it accepts user supplied query objects for filtering.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% means the likelihood of public exploitation is low at this time. The vulnerability is not yet listed in the CISA KEV catalog. Likely attack vectors are through web or API endpoints that accept query parameters without prior sanitization. An attacker can inject a $where or other JavaScript‑executing operator, leading to data disclosure or a denial‑of‑service by exhausting database resources.

Generated by OpenCVE AI on September 19, 2026 at 16:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Mongoid version that includes the operator guard fix
  • If an immediate update is not possible, modify application code to avoid passing unsanitized filter data to Mongoid query builders
  • Configure MongoDB to disable JavaScript execution in queries by setting the database to run in 'noexec' mode or removing the $where operator from allowed operators

Generated by OpenCVE AI on September 19, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.
Title NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:14:42.500Z

Reserved: 2026-09-18T16:51:39.476Z

Link: CVE-2026-93760

cve-icon Vulnrichment

Updated: 2026-09-21T18:14:35.463Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T18:18:34.780

Modified: 2026-09-24T16:07:38.610

Link: CVE-2026-93760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:34Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic