Executive brief
Mongoid is a Ruby object-document mapper that bridges Ruby applications to MongoDB databases. A vulnerability in how nested attributes are processed allows an authenticated user to modify records belonging to other users by directly referencing their database identifiers, potentially exposing and altering sensitive data across the application without proper authorization checks.
Technical details
An insecure direct object reference (IDOR) flaw in Mongoid's nested attributes handling allows authenticated attackers to bypass ownership and scoping restrictions. By crafting requests with arbitrary record identifiers, attackers can retrieve and modify records without authorization; the vulnerability exists because direct object references are processed without sufficient access control validation before lookup and update operations.
Affected products
- MongoDB Mongoid
Timeline
- 2026-09-18: disclosed