MongoDB BI Connector Transition Readiness Report: cross-site scripting
Medium6.9CVE-2026-76798 · Published Aug 28, 2026 · updated Sep 17, 2026
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| BI Connector Transition Readiness Report Product | >= 1.0.0, < 1.1.3 | 1.1.3 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | MongoDB BI Connector: null pointer dereference | High8.3 | 2.14.31 |
| Aug 28 | An unauthenticated party able to reach the port of a MongoDB Connector for BI | High8.7 | 2.14.31 |
| Aug 28 | MongoDB BI Connector: improper certificate validation | High8.7 | 2.14.31 |
| Aug 28 | A network-reachable client | High8.7 | 2.14.31 |
| Aug 28 | MongoDB BI Connector ODBC Driver: stack buffer overflow | High8.7 | 1.4.10 |
| Aug 28 | MongoDB BI Connector ODBC Driver: stack buffer overflow | Medium6.0 | 1.4.10 |