{"id":"CVE-2026-93762","published":"2026-09-18T18:18:35.053","lastModified":"2026-09-24T16:05:13.747","description":"Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-470"],"vendors":["mongodb"],"products":["mongoid"],"references":[{"url":"https://jira.mongodb.org/browse/MONGOID-5973","tags":["Permissions Required"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an unauthenticated party to obtain sensitive data and permanently delete documents by manipulating field names in query methods, posing a significant security risk.","exploitability":"Exploitation is relatively straightforward given the external field name manipulation, requiring only that the field name be controlled by an attacker.","blast_radius":"If exploited, the impact could be severe, leading to data breaches and loss of critical documents, affecting the integrity and confidentiality of the application's data.","remediation":"Disable the affected Mongoid query methods or upgrade to the latest version of Mongoid that addresses this vulnerability.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["data-disclosure","data-loss","query-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:01:43.390Z"}}