Mongoid IOR in nested attributes allows privilege escalation
CVE-2026-93758 Published on September 18, 2026
Cross-principal document update, theft, and deletion via unvalidated id in nested attributes
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This may result in unintended disclosure and unauthorized modification of data belonging to other users of the application.
Vulnerability Analysis
CVE-2026-93758 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an Insecure Direct Object Reference / IDOR Vulnerability?
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVE-2026-93758 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.
Affected Versions
MongoDB Inc. Mongoid:- Version 9.1.0 is affected.
- Version 9.0.0, <= 9.0.11 is affected.
- Version 8.1.0, <= 8.1.12 is affected.
- Version 8.0.0, <= 8.0.12 is affected.