Vulnerability Description
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongosql Transition Readiness Tool | < 1.1.3 |
Related Weaknesses (CWE)
References
- https://www.mongodb.com/docs/sql-interface/changelog/Vendor Advisory
FAQ
What is CVE-2026-76794?
CVE-2026-76794 is a vulnerability with a CVSS score of 4.6 (MEDIUM). MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause ...
How severe is CVE-2026-76794?
CVE-2026-76794 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76794?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongosql Transition Readiness Tool.