MEDIUM · 4.6

CVE-2026-76794

MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause ...

Vulnerability Description

MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MongodbMongosql Transition Readiness Tool< 1.1.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-76794?

CVE-2026-76794 is a vulnerability with a CVSS score of 4.6 (MEDIUM). MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause ...

How severe is CVE-2026-76794?

CVE-2026-76794 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-76794?

Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongosql Transition Readiness Tool.