CVE-2026-93762
EUVD-2026-8320318.09.2026, 18:18
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
Awaiting analysis
This vulnerability is currently awaiting analysis.