CVE-2026-76797Medium· 6.3▾ SunlitThe MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the clust…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.3%
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.
mongosql_transition_readiness_tool < 1.1.3Upgrade past the affected range:
mongosql_transition_readiness_tool 1.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76798Medium· 6.3The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context
CVE-2026-76794Medium· 4.6MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML
CVE-2026-9673Medium· 6.8Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed
CVE-2026-13062Medium· 6.5MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters
CVE-2026-13060Medium· 6.5$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access
CVE-2026-84962Medium· 4.2An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and…