Mongoid Query Builder Vulnerability Exposes Database to Unauthenticated Code Execution
CVE-2026-93759
8.8HIGH
What is CVE-2026-93759?
The Mongoid framework is susceptible to a serious flaw where it fails to properly neutralize string-typed query criteria sent to its query builder. This oversight allows an unauthenticated attacker to manipulate input, potentially leading to the execution of arbitrary server-side JavaScript code by the database engine. The consequences of this vulnerability include unauthorized disclosure of sensitive stored data, misdirected document writes, and overall degradation of database performance. It is critical for users of Mongoid to assess their vulnerability exposure and take appropriate actions to secure their applications.
Affected Version(s)
Mongoid 9.1.0
Mongoid 9.0.0 <= 9.0.11
Mongoid 8.1.0 <= 8.1.12