Junglewise Threat Intelligence

CVE-2026-93762: Mongoid unsafe reflection weakness in query path for embedded documents

CVE-2026-93762 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: MongoDB Mongoid. Vendors: MongoDB.

Executive brief

Mongoid, a popular MongoDB object-relational mapper, contains a flaw that allows attackers to pass malicious field names to in-memory query methods. Without authentication, an attacker can read sensitive data from stored documents or permanently delete records by exploiting unsafe reflection in how Mongoid constructs queries for nested objects.

Technical details

The vulnerability exists in Mongoid's handling of externally-supplied field names used in query path construction for embedded documents. The flaw stems from unsafe reflection that does not properly validate or sanitize field names before using them in in-memory query operations. An unauthenticated attacker can exploit this to exfiltrate stored document data or trigger destructive deletions of database records.

Affected products

  • MongoDB Mongoid

Timeline

  • 2026-09-18: disclosed

References

Related threats