Bug 2538719 (CVE-2026-93765)

Summary: CVE-2026-93765 mongoid: Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Mongoid. An unauthenticated remote attacker can exploit an unsafe reflection vulnerability by sending crafted input keys through an application that uses Mongoid for data persistence. This causes the application to execute unintended internal methods instead of performing standard field updates, which can result in unauthorized data deletion or a denial of service (DoS) due to an application crash.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2543148    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 20:09:27 UTC
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.