← Vulnerability feed

Vulnerability record · CVE-2026-93765 · published 18 September 2026

CVE-2026-93765: Mongodb mongoid vulnerability

Mongodb · Mongoid

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.

8.3 CVSS 4.0 High EPSS 0.51% · top 58.8% CWE-470 · CWE-470
8.3CVSS 4.0 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Sep 2026Last modified by NVD

Description

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/MONGOID-5973 Permissions Required

Track CVE-2026-93765 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-93762Mongodb mongoid vulnerabilityMongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field…EPSS 0.57%8.8CVE-2026-93759Mongodb mongoid code injection vulnerabilityMongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side Java…EPSS 0.40%8.7CVE-2026-93761Mongodb mongoid inefficient regular expression (redos) vulnerabilityAn inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated pa…EPSS 0.46%8.6CVE-2026-93758Mongodb mongoid insecure direct object reference vulnerabilityAn insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application p…EPSS 0.36%8.3CVE-2026-93760Mongodb mongoid vulnerabilityMongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building m…EPSS 0.47%7.1CVE-2026-93763Mongodb mongoid cleartext storage of sensitive data vulnerabilityA protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for …EPSS 0.15%7.1CVE-2026-93764Mongodb mongoid cleartext storage of sensitive data vulnerabilityMongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications …EPSS 0.15%9.4CVE-2026-82078PaperCut MF/NG unsafe dynamic class loading enables code executionPaperCut MF and NG instantiate database driver classes from configurable driver names without validating them against an allowlist of approved driver…KEVEPSS 3.8%analysed

Source: NIST National Vulnerability Database (record CVE-2026-93765), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.