Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76797— MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated Reports

Quick assessment

Affected
MongoDB BI Connector Transition Readiness Report
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoSQL 迁移就绪工具在生成 CSV 报告时,将数据库名和集合名直接写入报告中,未对电子表格软件将其视为公式的特殊前导字符进行转义或中和处理。如果某个用户对集群拥有写权限,他可以创建一个在电子表格应用中会被解释为公式的命名空间名称。当操作人员打开该生成的报告时,可能会导致报告内容的意外泄露,或在操作人员的工作站上执行外部内容。触发此问题需要:针对受影响的命名空间生成一份报告,并在电子表格应用中打开该报告。

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1567.001 · Exfiltration to Code Repository

Affected Version Matrix 1

VendorProduct Version RangeStatus
MongoDB BI Connector Transition Readiness Report 1.0.0< 1.1.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76797

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated Reports
Source: CVE Program / CVE List V5
Vulnerability Description
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1236
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB BI Connector Transition Readiness Report 1.0.0 ~ 1.1.3 -

II. Public POCs for CVE-2026-76797

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76797

登录查看更多情报信息。

Vendor Pages for CVE-2026-76797 (1)

Same Patch Batch · MongoDB · 2026-08-28 · 11 CVEs total

CVE-2026-81532 8.8 HIGH BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt
CVE-2026-77586 8.0 HIGH MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output
CVE-2026-81490 7.7 HIGH MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of
CVE-2026-81517 7.5 HIGH MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S
CVE-2026-81518 7.5 HIGH BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections
CVE-2026-81520 7.5 HIGH MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus
CVE-2026-81533 7.1 HIGH MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values
CVE-2026-76798 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports
CVE-2026-77184 5.2 MEDIUM MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O
CVE-2026-76794 4.6 MEDIUM MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da

IV. Related Vulnerabilities

V. Comments for CVE-2026-76797

No comments yet


Leave a comment