Record summary

CVE-2026-2302 has a selected CVSS score of 6.9 (medium).

Description

Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.0.0 to ≤ 7.6.1affected
8.0.0 to ≤ 8.0.12affected
8.1.0 to ≤ 8.1.12affected
9.0.0 to ≤ 9.0.10affected

References

2