SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76798

MEDIUM · CVSS 6.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MongoSQL Transition Readiness Tool is vulnerable due to improper encoding of query text and usernames from BI Connector log files in its generated HTML reports. This flaw allows an attacker with query access to manipulate log content, potentially disclosing sensitive information or misleading operators when reports are viewed in a browser. Organizations using the BI Connector should prioritize addressing this vulnerability to mitigate risks of information leakage and ensure data integrity.

CVE
CVE-2026-76798
Severity
MEDIUM
CVSS
6.3
EPSS
0.20%

Original NVD Description

The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required.

Related CVEs

Other vulnerabilities affecting the same vendor(s)