Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/MONGOID-5973 |
|
History
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records. | |
| Title | Data deletion and attribute disclosure via field-name method injection in in-memory queries | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-18T17:15:17.490Z
Reserved: 2026-09-18T16:51:40.941Z
Link: CVE-2026-93762
No data.
Status : Awaiting Analysis
Published: 2026-09-18T18:18:35.053
Modified: 2026-09-18T19:05:01.127
Link: CVE-2026-93762
No data.
OpenCVE Enrichment
No data.
Weaknesses