Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog/ |
|
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required. | |
| Title | MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-28T19:24:46.039Z
Reserved: 2026-08-19T19:18:12.867Z
Link: CVE-2026-76798
No data.
Status : Received
Published: 2026-08-28T20:19:55.263
Modified: 2026-08-28T20:19:55.263
Link: CVE-2026-76798
No data.
OpenCVE Enrichment
No data.