CVE-2026-93762: unauthenticated data disclosure and deletion in MongoDB Mongoid

An unauthenticated attacker can craft field-name input that abuses Mongoid's reflection logic to access and remove stored embedded documents, tracked as CVE-2026-93762. The issue spans many branches and releases, including 9.1.0; 9.0.0–9.0.11; 8.1.0–8.1.12; 8.0.0–8.0.12; 7.6.0–7.6.1; and 7.5.0–7.5.4. Exploitation leverages application calls that accept externally supplied field names for in-memory query operations, so an attacker does not need credentials to trigger disclosure or permanent deletion.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00573
CWE
CWE-470
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: an unauthenticated flaw with no fixed releases listed can expose and delete data; immediately restrict external access and sanitize any user-controlled field names in queries until vendor fixes are available.

What is CVE-2026-93762?

An unauthenticated attacker can craft field-name input that abuses Mongoid's reflection logic to access and remove stored embedded documents, tracked as CVE-2026-93762. The issue spans many branches and releases, including 9.1.0; 9.0.0–9.0.11; 8.1.0–8.1.12; 8.0.0–8.0.12; 7.6.0–7.6.1; and 7.5.0–7.5.4. Exploitation leverages application calls that accept externally supplied field names for in-memory query operations, so an attacker does not need credentials to trigger disclosure or permanent deletion.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of MongoDB Mongoid are affected?

BRANCHAFFECTEDFIXED
9.x9.1.0
9.x9.0.0 – 9.0.11
8.x8.1.0 – 8.1.12
8.x8.0.0 – 8.0.12
7.x7.6.0 – 7.6.1
7.x7.5.0 – 7.5.4

Is CVE-2026-93762 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-93762

  1. Prevent passing externally supplied field names into Mongoid query/reflection methods; validate and whitelist allowed fields in application code.
  2. Restrict exposure of applications using affected Mongoid versions to trusted networks and block unauthenticated access where possible.
  3. Enable and review application and database logs for unusual query patterns and deletions; implement alerting for suspicious activity.
  4. Apply vendor guidance or upgrade to patched Mongoid releases once the vendor publishes fixed versions.

Frequently asked questions

Is CVE-2026-93762 being actively exploited?

There are no public reports of exploitation of CVE-2026-93762 as of 2026-09-29.

Which Mongoid versions are affected by CVE-2026-93762?

Mongoid versions affected include 9.1.0; 9.0.0–9.0.11; 8.1.0–8.1.12; 8.0.0–8.0.12; 7.6.0–7.6.1; and 7.5.0–7.5.4.

Is there a patch for CVE-2026-93762?

No fixed Mongoid releases are listed for CVE-2026-93762; follow vendor advisories and apply upgrades when fixed versions are published.

Does CVE-2026-93762 require authentication?

No, the vulnerability in Mongoid can be exploited by an unauthenticated party supplying crafted field names to the affected query methods.

References