Description
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
Published: 2026-09-18
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Data theft and deletion
Action: Immediate Patch
AI Analysis

Impact

Mongoid's query path for embedded documents uses unsafe reflection, allowing a crafted externally supplied field name to be executed as code. This flaw permits any unauthenticated user to unintentionally expose stored document data and to permanently delete records, leading to confidentiality and integrity violations.

Affected Systems

MongoDB Inc.'s Mongoid library. No specific version information is provided in the advisory; administrators should verify which releases contain the vulnerability and ensure their installations are updated accordingly.

Risk and Exploitability

The CVSS score of 9.2 reflects a high severity vulnerability, yet the EPSS score is below 1%, indicating that exploitation is currently low probability. The likely attack vector is any interface that forwards user‑provided field names to Mongoid’s in‑memory query methods, with no need for authentication, based on the description. As the vulnerability is not listed in CISA’s KEV catalog, it is not known to be actively exploited in the wild, but the potential impact warrants prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 16:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑published patch or upgrade Mongoid to a version that eliminates unsafe reflection from query handling.
  • Whitelist acceptable field names and reject any that are not part of the documented schema before they reach query methods.
  • Disable or remove configuration options that permit dynamic field‑name injection in queries if the application does not require them.
  • Audit application logs for anomalous query patterns and update firewall rules to block suspicious requests.

Generated by OpenCVE AI on September 19, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
Title Data deletion and attribute disclosure via field-name method injection in in-memory queries
Weaknesses CWE-470
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:18:05.713Z

Reserved: 2026-09-18T16:51:40.941Z

Link: CVE-2026-93762

cve-icon Vulnrichment

Updated: 2026-09-21T18:17:22.215Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T18:18:35.053

Modified: 2026-09-24T16:05:13.747

Link: CVE-2026-93762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:38Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')