Cross-Site Scripting in MongoDB BI Connector Tool
CVE-2026-76798

6.9MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
28 August 2026

What is CVE-2026-76798?

The MongoDB BI Connector is susceptible to a Cross-Site Scripting vulnerability where the MongoSQL Transition Readiness Tool improperly handles query text and usernames from BI Connector log files. This flaw allows an attacker to influence the log content by issuing specific queries. Consequently, when an operator generates and views an HTML report, malicious markup may be executed by the browser. This situation can lead to the disclosure of sensitive data from other users' logged queries and usernames or possibly present misleading information. To exploit this vulnerability, an attacker must be able to issue queries through the BI Connector, making it crucial for users to secure their environments.

Affected Version(s)

BI Connector Transition Readiness Report 1.0.0 < 1.1.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.