← Vulnerability feed

Vulnerability record · CVE-2026-93760 · published 18 September 2026

CVE-2026-93760: Mongodb mongoid vulnerability

Mongodb · Mongoid

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.

8.3 CVSS 4.0 High EPSS 0.47% · top 62.0% CWE-943 · CWE-943
8.3CVSS 4.0 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Sep 2026Last modified by NVD

Description

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/MONGOID-5994 Permissions Required

Track CVE-2026-93760 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-93762Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field…EPSS 0.57%8.8CVE-2026-93759Mongodb mongoid code injection vulnerabilityMongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side Java…EPSS 0.40%8.7CVE-2026-93761Mongodb mongoid inefficient regular expression (redos) vulnerabilityAn inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated pa…EPSS 0.46%8.6CVE-2026-93758Mongodb mongoid insecure direct object reference vulnerabilityAn insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application p…EPSS 0.36%8.3CVE-2026-93765Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed thr…EPSS 0.51%7.1CVE-2026-93763Mongodb mongoid cleartext storage of sensitive data vulnerabilityA protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for …EPSS 0.15%7.1CVE-2026-93764Mongodb mongoid cleartext storage of sensitive data vulnerabilityMongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications …EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2026-93760), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.