Unescaped Identifiers in MongoDB Connector for BI Risk User Data Exposure
CVE-2026-77586

8.5HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
28 August 2026

What is CVE-2026-77586?

The MongoDB Connector for BI is vulnerable due to unescaped identifiers in the DDL text produced by SHOW CREATE statements. When MongoDB object names, such as collections or fields, are generated without proper escaping, a user with the ability to modify a sampled collection can craft names that prematurely terminate quoted identifiers. This flaw allows additional SQL code to be inserted into the output. Consequently, if this output is later executed on a SQL server by an operator or automated tool, the embedded commands can run under the current session's privileges, potentially leading to unauthorized actions on the database.

Affected Version(s)

BI Connector 2.1.0 < 2.14.31

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.