All CVEs
Vulnerability intelligence

CVE-2026-93760

MongoDB Inc. Mongoid CWE-943

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced database performance.

CVSS Score
8.3
High
EPSS — Exploit Probability
0.3%
Riskier than 21% of all CVEs · checked 2026-09-21
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Sep 21, 2026 · latest Sep 21, 2026

Coverage timeline

Related CVEs — MongoDB Inc.