Executive brief
Mongoid, a Ruby library for interacting with MongoDB databases, contains a weakness that allows unauthenticated attackers to invoke unintended internal methods through specially crafted input keys. An attacker can exploit this to delete database records and cause the application using Mongoid to stop responding, impacting both data integrity and application availability.
Technical details
The vulnerability is an unsafe reflection weakness in the document persistence layer's object-document mapping code. Unauthenticated input with malicious keys can bypass intended array field update logic and trigger internal method invocation, leading to unintended record removal and denial of service. The flaw affects how Mongoid processes embedded document updates when keys are passed through from an untrusted source.
Affected products
- MongoDB Mongoid <UNKNOWN>
Timeline
- 2026-09-18: disclosed