CVE-2026-93762 Overview
CVE-2026-93762 is an unsafe reflection weakness in Mongoid, the official object-document mapper (ODM) for MongoDB in Ruby. The flaw resides in the query path used for embedded documents. When an application forwards an externally supplied field name to certain in-memory query methods, an unauthenticated attacker can trigger unintended reflection on the target document. Exploitation can result in disclosure of stored document contents and permanent deletion of stored records. The vulnerability is tracked under CWE-470: Use of Externally-Controlled Input to Select Classes or Code.
Critical Impact
Unauthenticated attackers can read arbitrary embedded document fields and permanently remove stored records from MongoDB collections accessed through Mongoid.
Affected Products
- MongoDB Mongoid (Ruby ODM)
- Mongoid version 9.1.0
- Applications passing user-controlled field names to in-memory query methods on embedded documents
Discovery Timeline
- 2026-09-18 - CVE-2026-93762 published to the National Vulnerability Database (NVD)
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-93762
Vulnerability Analysis
Mongoid maps Ruby objects to MongoDB documents and supports embedded documents that live inside a parent record. Certain in-memory query helpers resolve field names by reflecting on the target document class at runtime. When the field name originates from untrusted input, the reflection step invokes methods or accesses attributes that were never intended to be reachable from a query context.
An attacker who controls the field parameter can direct the query engine to touch sensitive attributes on embedded documents, returning their values in query results. The same reflection path exposes destructive methods, which the query executes against the matched records. The result is disclosure of stored data and permanent removal of records without authentication.
The issue is tracked upstream in MongoDB JIRA Issue MONGOID-5973.
Root Cause
The root cause is unsafe reflection [CWE-470]. Mongoid's in-memory query path treats an externally supplied string as a trusted method or attribute name and dispatches it against the embedded document. The library performs no allowlist check against the document's declared schema fields before invoking the resolved symbol.
Attack Vector
The attack vector is the network. Any HTTP endpoint that forwards a request parameter, such as a sort key, filter field, or projection name, into a Mongoid in-memory query on an embedded association is reachable. No authentication and no user interaction are required. The attacker submits a crafted field name and observes the response or the resulting state change in the database.
No public proof-of-concept exploit code is available. Refer to MONGOID-5973 for vendor-provided technical detail.
Detection Methods for CVE-2026-93762
Indicators of Compromise
- Unexpected destroy, delete, or remove operations logged against embedded document collections without a corresponding authenticated user action.
- HTTP request parameters containing Ruby method names such as destroy_all, delete_all, send, or attribute names not defined in the application schema.
- Application logs showing Mongoid query methods invoked with field arguments that do not match any declared field on the target model.
Detection Strategies
- Instrument Mongoid query helpers to log the resolved field name and compare it against the model's declared schema fields.
- Add web application firewall rules that flag request parameters containing Ruby reflective method names when submitted to endpoints that perform querying or sorting.
- Review database audit logs for bulk deletions or reads on embedded documents that correlate with anomalous request patterns.
Monitoring Recommendations
- Enable MongoDB audit logging for delete and remove commands and forward the events to a centralized log store.
- Alert on statistically unusual delete volume per collection over short time windows.
- Track Rails or Sinatra controller parameters that flow into Mongoid query methods and alert when values fall outside the expected allowlist.
How to Mitigate CVE-2026-93762
Immediate Actions Required
- Inventory applications using Mongoid 9.1.0 and identify any code path where request parameters are passed as field names to in-memory query methods on embedded documents.
- Apply an allowlist at the controller layer that restricts field parameters to a fixed set of declared model attributes before the value reaches Mongoid.
- Restrict database credentials used by the application to the minimum privileges required, limiting the blast radius of a delete operation.
- Monitor MONGOID-5973 for the fixed release and upgrade as soon as it is published.
Patch Information
At the time of publication, the enriched CVE data lists no vendor patch URL. The upstream tracking issue is MONGOID-5973. Consult the MongoDB Mongoid release notes and upgrade to the first Mongoid release that references CVE-2026-93762 or MONGOID-5973 in its changelog.
Workarounds
- Reject request parameters whose values are not members of an explicit allowlist derived from Model.fields.keys.
- Convert externally supplied field names to symbols only after validation, and coerce unknown values to a safe default.
- Route in-memory queries on embedded documents through a wrapper method that raises on any field name outside the model's declared schema.
# Configuration example: allowlist field parameters in a Rails controller
# before calling any Mongoid in-memory query on embedded documents.
ALLOWED_SORT_FIELDS = %w[name created_at updated_at].freeze
def safe_field(param)
ALLOWED_SORT_FIELDS.include?(param) ? param : 'created_at'
end
# Usage:
# parent.embedded_items.asc(safe_field(params[:sort_by]))
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
