Reflection Weakness in MongoDB Driver for Embedded Document Queries by Mongoid
CVE-2026-93762
9.2CRITICAL
What is CVE-2026-93762?
The Mongoid framework contains a reflection vulnerability within its handling of embedded document queries. This specific weakness arises when an externally provided field name is executed by certain in-memory query methods. This flaw may allow an attacker without authentication to gain unauthorized access to sensitive document data, which can result in the exposure of private information or even the irreversible deletion of stored records. Implementing stringent input validation and restricting query access is paramount to mitigate the risks associated with this vulnerability.
Affected Version(s)
Mongoid 9.1.0
Mongoid 9.0.0 <= 9.0.11
Mongoid 8.1.0 <= 8.1.12