No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/MONGOID-5973 |
|
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongoid |
|
| Vendors & Products |
Mongodb
Mongodb mongoid |
Mon, 21 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive. | |
| Title | Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-21T18:47:20.835Z
Reserved: 2026-09-18T16:51:43.596Z
Link: CVE-2026-93765
Updated: 2026-09-21T18:47:16.471Z
Status : Undergoing Analysis
Published: 2026-09-18T17:17:07.730
Modified: 2026-09-21T19:17:18.297
Link: CVE-2026-93765
No data.
OpenCVE Enrichment
Updated: 2026-09-21T19:25:10Z