Mongoid IE: Unsanitized string leads to server-side JS execution
CVE-2026-93759 Published on September 18, 2026
Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.
Vulnerability Analysis
CVE-2026-93759 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2026-93759 has been classified to as a Code Injection vulnerability or weakness.
Affected Versions
MongoDB Inc. Mongoid:- Version 9.1.0 is affected.
- Version 9.0.0, <= 9.0.11 is affected.
- Version 8.1.0, <= 8.1.12 is affected.
- Version 8.0.0, <= 8.0.12 is affected.