MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog/ |
|
History
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display. | |
| Title | MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Database Metadata | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-28T19:23:07.804Z
Reserved: 2026-08-19T17:57:15.458Z
Link: CVE-2026-76794
No data.
Status : Awaiting Analysis
Published: 2026-08-28T20:19:54.987
Modified: 2026-08-28T21:16:15.740
Link: CVE-2026-76794
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:15:04Z
Weaknesses