Insecure Direct Object Reference in Mongoid Object-Document Mapper
CVE-2026-93758
8.6HIGH
What is CVE-2026-93758?
The Mongoid object-document mapper contains a vulnerability relating to its nested attributes handling that enables users with basic application privileges to access and manipulate records not belonging to them. By exploiting this unsafe reference, an attacker could bypass the expected ownership checks, potentially causing unauthorized disclosure and alterations to sensitive user data. This vulnerability highlights the need for stringent access controls and checks within application-level data management.
Affected Version(s)
Mongoid 9.1.0
Mongoid 9.0.0 <= 9.0.11
Mongoid 8.1.0 <= 8.1.12