CVE-2026-93760: MongoDB Mongoid

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.

Affected products

  • MongoDB Mongoid: from 8.0.0, before 8.0.13 (fixed in 8.0.13); from 8.1.0, before 8.1.13 (fixed in 8.1.13); from 9.0.0, before 9.0.12 (fixed in 9.0.12); version 9.1.0 only

Published 2026-09-18. Last modified 2026-09-24.