Reflection Weakness in MongoDB Driver for Embedded Document Queries by Mongoid
CVE-2026-93762

9.2CRITICAL

Key Information:

Vendor

MongoDB

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93762?

The Mongoid framework contains a reflection vulnerability within its handling of embedded document queries. This specific weakness arises when an externally provided field name is executed by certain in-memory query methods. This flaw may allow an attacker without authentication to gain unauthorized access to sensitive document data, which can result in the exposure of private information or even the irreversible deletion of stored records. Implementing stringent input validation and restricting query access is paramount to mitigate the risks associated with this vulnerability.

Affected Version(s)

Mongoid 9.1.0

Mongoid 9.0.0 <= 9.0.11

Mongoid 8.1.0 <= 8.1.12

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.