Skip to content
MongoDBCVE-2026-77184

MongoDB BI Connector: SQL injection

Medium5.7CVE-2026-77184 · Published Aug 28, 2026 · updated Aug 31, 2026

In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by SHOW CREATE statements without complete escaping of backslash characters. A user with permission to modify a collection's schema validator, in deployments configured to build their SQL schema from those validators, can cause additional SQL text to be embedded in that generated output. If an operator or automated tool later replays that generated statement against a SQL server, the additional text is executed with the privileges of that session.

MongoDB advisory

Affected versions

PackageAffectedFixed in
BI Connector
Product
>= 2.1.0, < 2.14.312.14.31
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-89

More MongoDB advisories

All MongoDB
Advisory
MongoDB BI Connector: null pointer dereference
High8.3Aug 28
An unauthenticated party able to reach the port of a MongoDB Connector for BI
High8.7Aug 28
MongoDB BI Connector: improper certificate validation
High8.7Aug 28
A network-reachable client
High8.7Aug 28
MongoDB BI Connector ODBC Driver: stack buffer overflow
High8.7Aug 28
MongoDB BI Connector ODBC Driver: stack buffer overflow
Medium6.0Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.