在 MongoDB for BI 连接器中,集合的 JSON Schema 校验器的描述文本会被整合到 语句返回的 DDL 中的注释文本里,但反斜杠字符未得到完整转义。在配置为根据这些校验器构建 SQL 架构的部署环境中,拥有修改集合 Schema 校验器权限的用户,可以在生成的输出中嵌入额外的 SQL 文本。如果后续由运维人员或自动化工具将该生成的语句在 SQL 服务器上重放执行,这段额外的文本将以此会话的权限被执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | BI Connector | 2.1.0< 2.14.31 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | BI Connector | 2.1.0 ~ 2.14.31 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81532 | 8.8 HIGH | BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt |
| CVE-2026-77586 | 8.0 HIGH | MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output |
| CVE-2026-81490 | 7.7 HIGH | MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of |
| CVE-2026-81517 | 7.5 HIGH | MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S |
| CVE-2026-81518 | 7.5 HIGH | BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections |
| CVE-2026-81520 | 7.5 HIGH | MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus |
| CVE-2026-81533 | 7.1 HIGH | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values |
| CVE-2026-76798 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports |
| CVE-2026-76797 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate |
| CVE-2026-76794 | 4.6 MEDIUM | MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da |
No comments yet