Description
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.
Published: 2026-09-18
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Data deletion and application crash
Action: Immediate Patch
AI Analysis

Impact

Mongoid contains an unsafe reflection weakness in its document persistence layer. Keys supplied by an unauthenticated party can be passed through the embedding application and cause internal method invocation instead of the intended array field update. This flaw can result in unintended removal of stored records and can make the embedding application become unresponsive as a denial‑of‑service condition.

Affected Systems

The vulnerability affects Mongoid, MongoDB Inc.'s object‑document mapping library. No specific version information is provided in the advisory, so any deployment of Mongoid that does not guard against unvalidated input may be affected. Applications that embed Mongoid without proper input validation are at risk.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. The EPSS score of less than 1 % suggests that, while exploit attempts are unlikely at present, the probability is non‑zero. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated user sending crafted input to the application layer, which forwards the data to Mongoid. By doing so, an attacker can delete arbitrary documents and trigger a crash or denial of service without needing privileged database access.

Generated by OpenCVE AI on September 19, 2026 at 16:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Mongoid patch that resolves the unsafe reflection issue.
  • Configure the application to validate or whitelist input keys before passing them to Mongoid, thereby preventing unintended method dispatch.
  • Maintain regular backups of collections and monitor application logs for unexpected deletions or crashes; enable strict mode if supported.

Generated by OpenCVE AI on September 19, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.
Title Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation
Weaknesses CWE-470
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-21T18:47:20.835Z

Reserved: 2026-09-18T16:51:43.596Z

Link: CVE-2026-93765

cve-icon Vulnrichment

Updated: 2026-09-21T18:47:16.471Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T17:17:07.730

Modified: 2026-09-25T14:10:39.357

Link: CVE-2026-93765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:10Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')