MongoSQL Transition Readiness Tool XSS via Unencoded Metadata
CVE-2026-76794 Published on August 28, 2026
MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Database Metadata
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display.
Vulnerability Analysis
CVE-2026-76794 is exploitable with network access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-76794 has been classified to as a XSS vulnerability or weakness.
Affected Versions
MongoDB BI Connector Transition Readiness Report:- Version 1.0.0 and below 1.1.3 is affected.