@apexsecurity1: The vulnerability occurs because the application trusts user-supplied JSON and passes it directly into a MongoDB query without validating or sanitizing it, allowing attackers to inject query operators like $regex and $ne that change the intended authentication logic and bypass normal username and password verification. #cybersecurity