SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-93762

CRITICAL · CVSS 9.8 EPSS 0.57%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

Mongoid is vulnerable due to an unsafe reflection weakness in its query path for embedded documents, allowing unauthenticated users to exploit this flaw. This could lead to unintended disclosure of sensitive stored document data and the potential for permanent deletion of records. Organizations utilizing Mongoid should prioritize addressing this vulnerability to safeguard their data integrity and confidentiality.

CVE
CVE-2026-93762
Severity
CRITICAL
CVSS
9.8
EPSS
0.57%

Original NVD Description

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

Related CVEs

Other vulnerabilities affecting the same vendor(s)