← Back to search

CVE-2026-93765

9.1 CRITICAL

Published 2026-09-18 · Updated 2026-09-21

AI risk analysis

Summary
This flaw in Mongoid allows unauthenticated input to trigger unintended internal method invocations, potentially leading to data loss and application unresponsiveness.
Exploitability
Exploitation requires unauthenticated input with specific keys, making it moderately difficult. The embedding application must be configured to use Mongoid.
Blast radius
If exploited, this could result in significant data loss and application downtime, impacting the entire system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of Mongoid, specifically version 6.3.0 or later.
data-lossunauthenticatedinternal-method-invocation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses

CWE-470

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.