Executive brief
Mongoid, a popular MongoDB object-relational mapper, contains a flaw that allows attackers to pass malicious field names to in-memory query methods. Without authentication, an attacker can read sensitive data from stored documents or permanently delete records by exploiting unsafe reflection in how Mongoid constructs queries for nested objects.
Technical details
The vulnerability exists in Mongoid's handling of externally-supplied field names used in query path construction for embedded documents. The flaw stems from unsafe reflection that does not properly validate or sanitize field names before using them in in-memory query operations. An unauthenticated attacker can exploit this to exfiltrate stored document data or trigger destructive deletions of database records.
Affected products
- MongoDB Mongoid
Timeline
- 2026-09-18: disclosed