Skip to content
MongoDBCVE-2026-76798

MongoDB BI Connector Transition Readiness Report: cross-site scripting

Medium6.9CVE-2026-76798 · Published Aug 28, 2026 · updated Sep 17, 2026

The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required.

MongoDB advisory

Affected versions

PackageAffectedFixed in
BI Connector Transition Readiness Report
Product
>= 1.0.0, < 1.1.31.1.3
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More MongoDB advisories

All MongoDB
Advisory
MongoDB BI Connector: null pointer dereference
High8.3Aug 28
An unauthenticated party able to reach the port of a MongoDB Connector for BI
High8.7Aug 28
MongoDB BI Connector: improper certificate validation
High8.7Aug 28
A network-reachable client
High8.7Aug 28
MongoDB BI Connector ODBC Driver: stack buffer overflow
High8.7Aug 28
MongoDB BI Connector ODBC Driver: stack buffer overflow
Medium6.0Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.