DIRAS TAKE
Urgent: treat this as high priority because the flaw can be triggered without authentication and no fixed release is yet listed; immediately block or validate untrusted keys forwarded into Mongoid and limit public exposure of services that accept user-supplied document data.
What is CVE-2026-93765?
An unauthenticated party can send crafted input keys that, when passed through by an embedding application, trigger unintended internal method invocation in Mongoid, potentially causing removal of stored records or application unresponsiveness. CVE-2026-93765 affects Mongoid 8.0.0–8.0.12, 8.1.0–8.1.12, 9.0.0–9.0.11 and 9.1.0. Exploitation requires an attacker-controlled input whose keys are forwarded into Mongoid by the host application; no credentials are required within Mongoid itself.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Which versions of MongoDB Mongoid are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 9.x | 9.1.0 | |
| 9.x | 9.0.0 – 9.0.11 | |
| 8.x | 8.1.0 – 8.1.12 | |
| 8.x | 8.0.0 – 8.0.12 |
Is CVE-2026-93765 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-93765
- Apply vendor guidance if released and track MongoDB/Mongoid advisories for a fixed release.
- Prevent untrusted input keys from being forwarded into Mongoid by validating or whitelisting allowed fields in the embedding application.
- Restrict network exposure of services that accept JSON or form data bound to Mongoid models, and require authentication where possible.
- Monitor application logs for unexpected method-invocation patterns and for deletions or failures linked to incoming payloads.
Frequently asked questions
Is CVE-2026-93765 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Mongoid versions are affected by CVE-2026-93765?
The vulnerability affects Mongoid versions 8.0.0–8.0.12, 8.1.0–8.1.12, 9.0.0–9.0.11 and 9.1.0.
Is there a patch for CVE-2026-93765?
No fixed versions are listed in the available vendor information; monitor MongoDB/Mongoid advisories for an official patch.
Does CVE-2026-93765 require authentication?
No — the issue can be triggered by untrusted input keys forwarded by an embedding application without authentication to Mongoid.
References
- nvd.nist.gov/vuln/detail/CVE-2026-93765
- cve.org/CVERecord?id=CVE-2026-93765
- jira.mongodb.org/browse/MONGOID-5973
- All MongoDB CVEs on CVE Radar
- CVEs published in September 2026