← Vulnerability feed

Vulnerability record · CVE-2026-93758 · published 18 September 2026

CVE-2026-93758: Mongodb mongoid insecure direct object reference vulnerability

Mongodb · Mongoid

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This may result in unintended disclosure and unauthorized modification of data belonging to other users of the application.

8.6 CVSS 4.0 High EPSS 0.36% · top 73.2% CWE-639 · Insecure direct object reference
8.6CVSS 4.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Sep 2026Last modified by NVD

Description

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This may result in unintended disclosure and unauthorized modification of data belonging to other users of the application.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-93758 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-93762Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field…EPSS 0.57%8.8CVE-2026-93759Mongodb mongoid code injection vulnerabilityMongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side Java…EPSS 0.40%8.7CVE-2026-93761Mongodb mongoid inefficient regular expression (redos) vulnerabilityAn inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated pa…EPSS 0.46%8.3CVE-2026-93760Mongodb mongoid vulnerabilityMongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building m…EPSS 0.47%8.3CVE-2026-93765Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed thr…EPSS 0.51%7.1CVE-2026-93763Mongodb mongoid cleartext storage of sensitive data vulnerabilityA protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for …EPSS 0.15%7.1CVE-2026-93764Mongodb mongoid cleartext storage of sensitive data vulnerabilityMongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications …EPSS 0.15%8.4CVE-2026-55255Langflow IDOR in responses endpoint allows cross-user flow executionLangflow before 1.9.1 has an insecure direct object reference in the /api/v1/responses endpoint. An authenticated attacker can supply another user's …KEVEPSS 0.89%analysed

Source: NIST National Vulnerability Database (record CVE-2026-93758), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.