Junglewise Threat Intelligence

CVE-2026-93765: Mongoid unsafe reflection in document persistence layer

CVE-2026-93765 · Severity: critical · CVSS 9.1 · Published 2026-09-18

Technologies: MongoDB Mongoid. Vendors: MongoDB.

Executive brief

Mongoid, a Ruby library for interacting with MongoDB databases, contains a weakness that allows unauthenticated attackers to invoke unintended internal methods through specially crafted input keys. An attacker can exploit this to delete database records and cause the application using Mongoid to stop responding, impacting both data integrity and application availability.

Technical details

The vulnerability is an unsafe reflection weakness in the document persistence layer's object-document mapping code. Unauthenticated input with malicious keys can bypass intended array field update logic and trigger internal method invocation, leading to unintended record removal and denial of service. The flaw affects how Mongoid processes embedded document updates when keys are passed through from an untrusted source.

Affected products

  • MongoDB Mongoid <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References

Related threats