Mongoid Query Builder Vulnerability Exposes Database to Unauthenticated Code Execution
CVE-2026-93759

8.8HIGH

Key Information:

Vendor

MongoDB

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93759?

The Mongoid framework is susceptible to a serious flaw where it fails to properly neutralize string-typed query criteria sent to its query builder. This oversight allows an unauthenticated attacker to manipulate input, potentially leading to the execution of arbitrary server-side JavaScript code by the database engine. The consequences of this vulnerability include unauthorized disclosure of sensitive stored data, misdirected document writes, and overall degradation of database performance. It is critical for users of Mongoid to assess their vulnerability exposure and take appropriate actions to secure their applications.

Affected Version(s)

Mongoid 9.1.0

Mongoid 9.0.0 <= 9.0.11

Mongoid 8.1.0 <= 8.1.12

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.