Unescaped Identifiers in MongoDB Connector for BI Risk User Data Exposure
CVE-2026-77586
8.5HIGH
What is CVE-2026-77586?
The MongoDB Connector for BI is vulnerable due to unescaped identifiers in the DDL text produced by SHOW CREATE statements. When MongoDB object names, such as collections or fields, are generated without proper escaping, a user with the ability to modify a sampled collection can craft names that prematurely terminate quoted identifiers. This flaw allows additional SQL code to be inserted into the output. Consequently, if this output is later executed on a SQL server by an operator or automated tool, the embedded commands can run under the current session's privileges, potentially leading to unauthorized actions on the database.
Affected Version(s)
BI Connector 2.1.0 < 2.14.31