Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/MONGOID-5973 |
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive. | |
| Title | Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-18T17:01:09.031Z
Reserved: 2026-09-18T16:51:43.596Z
Link: CVE-2026-93765
No data.
Status : Awaiting Analysis
Published: 2026-09-18T17:17:07.730
Modified: 2026-09-18T19:05:01.127
Link: CVE-2026-93765
No data.
OpenCVE Enrichment
No data.
