← Back to search

CVE-2026-93762

9.8 CRITICAL

Published 2026-09-18 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an unauthenticated party to obtain sensitive data and permanently delete documents by manipulating field names in query methods, posing a significant security risk.
Exploitability
Exploitation is relatively straightforward given the external field name manipulation, requiring only that the field name be controlled by an attacker.
Blast radius
If exploited, the impact could be severe, leading to data breaches and loss of critical documents, affecting the integrity and confidentiality of the application's data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected Mongoid query methods or upgrade to the latest version of Mongoid that addresses this vulnerability.
data-disclosuredata-lossquery-injection

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-470

Vendors

mongodb

Products

mongoid

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.