Vulnerability intelligence
CVE-2026-93759
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.2%
Riskier than 15% of all CVEs · checked 2026-09-21
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Sep 21, 2026 · latest Sep 21, 2026
Coverage timeline
-
MongoDB Libraries Hit by 14 Flaws Risking Data Theft and Losssecurityonline.info · Sep 21, 2026