DIRAS TAKE
Urgent: an unauthenticated flaw with no fixed releases listed can expose and delete data; immediately restrict external access and sanitize any user-controlled field names in queries until vendor fixes are available.
What is CVE-2026-93762?
An unauthenticated attacker can craft field-name input that abuses Mongoid's reflection logic to access and remove stored embedded documents, tracked as CVE-2026-93762. The issue spans many branches and releases, including 9.1.0; 9.0.0–9.0.11; 8.1.0–8.1.12; 8.0.0–8.0.12; 7.6.0–7.6.1; and 7.5.0–7.5.4. Exploitation leverages application calls that accept externally supplied field names for in-memory query operations, so an attacker does not need credentials to trigger disclosure or permanent deletion.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of MongoDB Mongoid are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 9.x | 9.1.0 | |
| 9.x | 9.0.0 – 9.0.11 | |
| 8.x | 8.1.0 – 8.1.12 | |
| 8.x | 8.0.0 – 8.0.12 | |
| 7.x | 7.6.0 – 7.6.1 | |
| 7.x | 7.5.0 – 7.5.4 |
Is CVE-2026-93762 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-93762
- Prevent passing externally supplied field names into Mongoid query/reflection methods; validate and whitelist allowed fields in application code.
- Restrict exposure of applications using affected Mongoid versions to trusted networks and block unauthenticated access where possible.
- Enable and review application and database logs for unusual query patterns and deletions; implement alerting for suspicious activity.
- Apply vendor guidance or upgrade to patched Mongoid releases once the vendor publishes fixed versions.
Frequently asked questions
Is CVE-2026-93762 being actively exploited?
There are no public reports of exploitation of CVE-2026-93762 as of 2026-09-29.
Which Mongoid versions are affected by CVE-2026-93762?
Mongoid versions affected include 9.1.0; 9.0.0–9.0.11; 8.1.0–8.1.12; 8.0.0–8.0.12; 7.6.0–7.6.1; and 7.5.0–7.5.4.
Is there a patch for CVE-2026-93762?
No fixed Mongoid releases are listed for CVE-2026-93762; follow vendor advisories and apply upgrades when fixed versions are published.
Does CVE-2026-93762 require authentication?
No, the vulnerability in Mongoid can be exploited by an unauthenticated party supplying crafted field names to the affected query methods.
References
- nvd.nist.gov/vuln/detail/CVE-2026-93762
- cve.org/CVERecord?id=CVE-2026-93762
- jira.mongodb.org/browse/MONGOID-5973
- All MongoDB CVEs on CVE Radar
- CVEs published in September 2026