CVE-2026-93762
9.8 CRITICALPublished 2026-09-18 · Updated 2026-09-24
AI risk analysis
- Summary
- The flaw allows an unauthenticated party to obtain sensitive data and permanently delete documents by manipulating field names in query methods, posing a significant security risk.
- Exploitability
- Exploitation is relatively straightforward given the external field name manipulation, requiring only that the field name be controlled by an attacker.
- Blast radius
- If exploited, the impact could be severe, leading to data breaches and loss of critical documents, affecting the integrity and confidentiality of the application's data.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected Mongoid query methods or upgrade to the latest version of Mongoid that addresses this vulnerability.
data-disclosuredata-lossquery-injection
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-470
Vendors
mongodb
Products
mongoid
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-93765
- HIGHCVE-2026-12265
- HIGHCVE-2026-48826PoC
- HIGHCVE-2026-48975PoC
- MEDIUMCVE-2026-61744PoC
- CRITICALCVE-2026-69703PoC
- HIGHCVE-2026-70494PoC
- HIGHCVE-2026-7444
Related by shared AI tags and CWE weakness class. Browse the full archive.