CVE-2026-93762
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | Mongoid | 9.1.0 | affected |
| MongoDB Inc. | Mongoid | 9.0.0 <= 9.0.11 | affected |
| MongoDB Inc. | Mongoid | 8.1.0 <= 8.1.12 | affected |
| MongoDB Inc. | Mongoid | 8.0.0 <= 8.0.12 | affected |
| MongoDB Inc. | Mongoid | 7.6.0 <= 7.6.1 | affected |
| MongoDB Inc. | Mongoid | 7.5.0 <= 7.5.4 | affected |
Weaknesses
- CWE-470: CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.