Skip to main content
Vulnerability Database/CVE-2026-93765

CVE-2026-93765: MongoDB Mongoid RCE Vulnerability

CVE-2026-93765 is an unsafe reflection weakness in MongoDB Mongoid's document persistence layer that enables remote code execution through malicious input keys. This article covers the technical details, affected versions, security impact, and recommended mitigation strategies.

Published:

CVE-2026-93765 Overview

CVE-2026-93765 is an unsafe reflection vulnerability [CWE-470] in Mongoid, the official object-document mapper (ODM) for MongoDB in Ruby. The flaw resides in the document persistence layer, where user-controlled input keys are passed through to internal reflection logic without validation. An unauthenticated attacker who can influence the keys of an array field update through an embedding application can trigger unintended internal method invocation. Successful exploitation leads to removal of stored records and can render the embedding application unresponsive, resulting in data integrity loss and denial of service.

Critical Impact

Unauthenticated attackers can invoke unintended internal Mongoid methods through crafted input keys, causing destruction of stored MongoDB records and application unresponsiveness.

Affected Products

  • MongoDB Mongoid 9.1.0
  • MongoDB Mongoid prior versions covered by the advisory
  • Ruby applications embedding Mongoid as their MongoDB ODM

Discovery Timeline

  • 2026-09-18 - CVE-2026-93765 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2026-93765

Vulnerability Analysis

Mongoid's persistence layer accepts hash-style input to update embedded document fields, including array fields. During the update path, key names supplied by the caller are reflected onto internal Ruby methods rather than being restricted to declared field setters. When an embedding web application forwards untrusted parameters directly into a Mongoid update, an attacker chooses key names that resolve to sensitive internal methods.

The reflected invocation replaces the intended array field mutation with an arbitrary method call on the document or its persistence context. Depending on the resolved method, the effect ranges from deleting the target document and its embedded children to entering paths that block the request handler. The vulnerability requires no authentication when the embedding application exposes the affected update route.

Root Cause

The root cause is classified under [CWE-470] Use of Externally-Controlled Input to Select Classes or Code, commonly referred to as unsafe reflection. Mongoid dispatches on caller-supplied key strings without enforcing an allow-list of legitimate field names. Any Ruby method reachable on the target object becomes a valid dispatch target when the key matches its name.

Attack Vector

Exploitation occurs over the network against any application that exposes a Mongoid update operation and forwards request parameters into an array field update without key filtering. The attacker submits an HTTP request whose JSON or form body includes a key crafted to match an internal Mongoid or Ruby method name. Mongoid then invokes that method during persistence, replacing the expected array modification with destructive or blocking behavior. The vulnerability mechanism is described in the vendor tracking issue at MongoDB Jira Issue MONGOID-5973.

Detection Methods for CVE-2026-93765

Indicators of Compromise

  • Unexpected delete, destroy, or remove operations recorded in MongoDB audit logs against documents targeted by user-facing update endpoints.
  • Application error logs showing NoMethodError, unexpected method dispatch, or stack traces originating in Mongoid::Persistable when handling user input.
  • HTTP request bodies containing parameter keys that match Ruby or Mongoid internal method names such as destroy, delete_all, or send.
  • Sudden drops in collection document counts that correlate with request traffic to Mongoid-backed endpoints.

Detection Strategies

  • Instrument Mongoid update paths to log the full set of keys received from untrusted sources and alert on keys outside the declared field allow-list.
  • Correlate MongoDB server logs with application access logs to identify update requests that trigger document deletions or unusually long-running operations.
  • Deploy web application firewall rules that flag JSON bodies containing reserved Ruby method names as top-level or nested keys.

Monitoring Recommendations

  • Monitor application worker responsiveness and thread saturation on endpoints that call Mongoid persistence methods with request-derived hashes.
  • Track MongoDB collection size and document count baselines to identify anomalous mass deletions.
  • Enable Ruby application performance monitoring (APM) traces on Mongoid update spans to surface unexpected method invocations.

How to Mitigate CVE-2026-93765

Immediate Actions Required

  • Upgrade Mongoid to the fixed release identified in the vendor advisory as soon as it is published on the MongoDB Jira issue MONGOID-5973.
  • Audit application controllers and service objects for calls that pass unfiltered params hashes into Mongoid update, push, or array mutation methods.
  • Enforce strong parameter filtering using Rails strong_parameters or an equivalent allow-list mechanism on every endpoint that reaches Mongoid persistence.
  • Restrict database user permissions so the application account cannot perform destructive operations outside the collections it must modify.

Patch Information

MongoDB tracks the fix in MongoDB Jira Issue MONGOID-5973. Consult that issue for the fixed Mongoid version and upgrade guidance. Applications running Mongoid 9.1.0 or earlier releases covered by the advisory should upgrade once the patched gem is available and redeploy dependent services.

Workarounds

  • Wrap all Mongoid update calls to explicitly extract only permitted field names before passing input into persistence methods.
  • Reject inbound request keys whose names match Ruby reserved methods or Mongoid internal API names at the controller boundary.
  • Isolate Mongoid-backed endpoints behind authentication and authorization checks to reduce the unauthenticated attack surface.
bash
# Configuration example: Rails strong parameters allow-list
# Restrict incoming keys to declared document fields before Mongoid update
def document_params
  params.require(:document).permit(:title, :status, tags: [])
end

# Then call update with the filtered hash
# document.update(document_params)

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.