Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-93762: Mongoid lets attackers delete data and view hidden fields
CVE-2026-93762 · published 10 days ago
Summary
Mongoid, the Ruby library that connects applications to MongoDB, can be tricked into revealing private document information and deleting records when it processes a field name supplied from outside. This occurs because the library does not properly check the field name before using it in certain internal searches. Upgrade to the latest Mongoid release and ensure any user‑provided field names are validated before use.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mongodb inc. | mongoid | 9.1.0 |
Original advisory text
Data deletion and attribute disclosure via field-name method injection in in-memory queries
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
References
Severity
9.9
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta