← Vulnerability feed

Vulnerability record · CVE-2026-93759 · published 18 September 2026

CVE-2026-93759: Mongodb mongoid code injection vulnerability

Mongodb · Mongoid

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.

8.8 CVSS 4.0 High EPSS 0.40% · top 68.5% CWE-94 · Code injection
8.8CVSS 4.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Sep 2026Last modified by NVD

Description

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/MONGOID-5993 Permissions Required

Track CVE-2026-93759 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-93762Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field…EPSS 0.57%8.7CVE-2026-93761Mongodb mongoid inefficient regular expression (redos) vulnerabilityAn inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated pa…EPSS 0.46%8.6CVE-2026-93758Mongodb mongoid insecure direct object reference vulnerabilityAn insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application p…EPSS 0.36%8.3CVE-2026-93760Mongodb mongoid vulnerabilityMongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building m…EPSS 0.47%8.3CVE-2026-93765Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed thr…EPSS 0.51%7.1CVE-2026-93763Mongodb mongoid cleartext storage of sensitive data vulnerabilityA protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for …EPSS 0.15%7.1CVE-2026-93764Mongodb mongoid cleartext storage of sensitive data vulnerabilityMongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications …EPSS 0.15%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2026-93759), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.