VYPR

Mongosql Transition Readiness Tool

by Mongosql

CVEs (3)

  • CVE-2026-76798MedAug 28, 2026
    risk 0.41cvss 6.3epss

    The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup…

  • CVE-2026-76797MedAug 28, 2026
    risk 0.41cvss 6.3epss

    The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is…

  • CVE-2026-76794MedAug 28, 2026
    risk 0.30cvss 4.6epss

    MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report,…