CVE-2026-93759
8.6 HIGHPublished 2026-09-18 · Updated 2026-09-24
AI risk analysis
- Summary
- The flaw allows an unauthenticated attacker to inject server-side JavaScript code into MongoDB queries via the Mongoid ORM, potentially leading to data exposure and performance degradation.
- Exploitability
- Exploitation requires control over the query parameter supplied to Mongoid, making it moderately hard to exploit without access to the application's input flow.
- Blast radius
- If exploited, the impact could range from data leakage to performance issues, affecting any application using Mongoid for database interactions.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected Mongoid feature or upgrade to a version that mitigates this vulnerability, such as Mongoid 7.0.0 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Weaknesses
CWE-94
Vendors
mongodb
Products
mongoid
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-16623
- CRITICALCVE-2026-18162
- HIGHCVE-2026-19804
- CRITICALCVE-2026-39117
- HIGHCVE-2026-4327
- HIGHCVE-2026-46581PoC
- HIGHCVE-2026-51997PoC
- CRITICALCVE-2026-62104
Related by shared AI tags and CWE weakness class. Browse the full archive.