Database Vulnerability in MongoDB Transition Readiness Tool Reveals Sensitive Data
CVE-2026-76797

5.8MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
28 August 2026

What is CVE-2026-76797?

The MongoDB Transition Readiness Tool has a significant vulnerability where it improperly handles database and collection names in its generated CSV reports. When these reports are opened in spreadsheet applications, leading characters that are treated as formulas can lead to unintended data disclosure or execution of external content. This occurs if a user with write privileges selects a namespace name that is then evaluated as a formula. This flaw requires generating a report for the affected namespace and subsequently opening it in a spreadsheet application, posing risks to confidential information.

Affected Version(s)

BI Connector Transition Readiness Report 1.0.0 < 1.1.3

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.