Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76798— MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports

Quick assessment

Affected
MongoDB BI Connector Transition Readiness Report
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段文字描述了一个特定的安全漏洞,主要涉及 HTML 报告生成时的编码问题。为了保持技术术语的准确性,同时确保中文表达自然流畅,我进行了如下翻译: MongoSQL 过渡就绪工具(Transition Readiness Tool)将从 BI 连接器(BI Connector)日志文件中读取的查询文本和用户名写入其生成的 HTML 报告,但未针对该输出上下文进行编码处理。能够通过 BI 连接器发出查询的用户可以影响日志内容,使得查询中提供的标记(markup)在操作员稍后生成并打开该报告时,会被浏览器解析执行。这可

CVSS 6.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
MongoDB BI Connector Transition Readiness Report 1.0.0< 1.1.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76798

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports
Source: CVE Program / CVE List V5
Vulnerability Description
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB BI Connector Transition Readiness Report 1.0.0 ~ 1.1.3 -

II. Public POCs for CVE-2026-76798

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76798

登录查看更多情报信息。

Vendor Pages for CVE-2026-76798 (1)

Same Patch Batch · MongoDB · 2026-08-28 · 11 CVEs total

CVE-2026-81532 8.8 HIGH BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt
CVE-2026-77586 8.0 HIGH MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output
CVE-2026-81490 7.7 HIGH MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of
CVE-2026-81517 7.5 HIGH MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S
CVE-2026-81518 7.5 HIGH BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections
CVE-2026-81520 7.5 HIGH MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus
CVE-2026-81533 7.1 HIGH MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values
CVE-2026-76797 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate
CVE-2026-77184 5.2 MEDIUM MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O
CVE-2026-76794 4.6 MEDIUM MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da

IV. Related Vulnerabilities

V. Comments for CVE-2026-76798

No comments yet


Leave a comment