CVE-2026-76798
- EPSS 0.2%
- Veröffentlicht 28.08.2026 19:24:46
- Zuletzt bearbeitet 17.09.2026 14:37:30
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence...
CVE-2026-76797
- EPSS 0.25%
- Veröffentlicht 28.08.2026 19:24:07
- Zuletzt bearbeitet 17.09.2026 14:37:45
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose...
CVE-2026-76794
- EPSS 0.16%
- Veröffentlicht 28.08.2026 19:23:07
- Zuletzt bearbeitet 17.09.2026 14:37:25
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and...