CRITICAL 9.2 NVD
CVE-2026-93762
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to ce
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
References
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-18 via NVD.
Risk Timeline
CVE Disclosed2026-09-18 · -1 days ago
Remediation Resources
Analysis & PoC
jira.mongodb.org/browse/MONGOID-5973
vulnfeed aggregates 14649 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.