SQL Injection Vulnerability in MongoDB Connector for BI
CVE-2026-77184

5.6MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
28 August 2026

What is CVE-2026-77184?

A security issue exists in the MongoDB Connector for BI where the JSON schema validator's description text can be improperly handled in SQL query outputs. When a user with appropriate privileges modifies the schema validator, the lack of proper escaping for backslash characters allows unintended SQL text to be included. This flaw poses a risk as any generated SQL statements containing the extra text may be executed on a SQL server, leveraging the user's session privileges, potentially leading to unauthorized access or data manipulation. It is crucial for users to ensure robust security measures are in place to prevent exploitation of this vulnerability.

Affected Version(s)

BI Connector 2.1.0 < 2.14.31

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.