MongoDBCVE-2026-93765
MongoDB Mongoid: unsafe reflection
High8.3CVE-2026-93765 · Published Sep 18, 2026 · updated Sep 25, 2026
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Mongoid Product | <= 9.1.0 | No fix yet |
| >= 9.0.0, <= 9.0.11 | No fix yet | |
| >= 8.1.0, <= 8.1.12 | No fix yet | |
| >= 8.0.0, <= 8.0.12 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-470
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | MongoDB Mongoid: unsafe reflection | Critical9.2 | No fix yet |
| Sep 18 | MongoDB Mongoid: information disclosure | High7.1 | No fix yet |
| Sep 18 | MongoDB Mongoid: cleartext storage | High7.1 | No fix yet |
| Sep 18 | MongoDB Mongoid: code injection | High8.8 | No fix yet |
| Sep 18 | Mongoid does not restrict | High8.3 | No fix yet |
| Sep 18 | MongoDB Mongoid: regular expression denial of service | High8.7 | No fix yet |