CVE-2026-93760: MongoDB Mongoid
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.
Affected products
- MongoDB Mongoid: from 8.0.0, before 8.0.13 (fixed in 8.0.13); from 8.1.0, before 8.1.13 (fixed in 8.1.13); from 9.0.0, before 9.0.12 (fixed in 9.0.12); version 9.1.0 only
Published 2026-09-18. Last modified 2026-09-24.