CVE-2026-76797

CVE-2026-76797 is a medium-severity vulnerability in Mongodb Mongosql Transition Readiness Tool with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1236.

Key facts

Description

The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.

Frequently asked questions

What is CVE-2026-76797?
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.
How severe is CVE-2026-76797?
CVE-2026-76797 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is high, integrity low, and availability none.
Is CVE-2026-76797 being actively exploited?
It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (27th percentile), an estimate of the probability of exploitation in the next 30 days.
What products are affected by CVE-2026-76797?
CVE-2026-76797 affects Mongodb Mongosql Transition Readiness Tool. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-76797?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
When was CVE-2026-76797 published?
CVE-2026-76797 was published on 2026-08-28 and last updated on 2026-09-17.

References

Affected products (1)

More vulnerabilities in Mongodb Mongosql Transition Readiness Tool

All CVEs affecting Mongodb Mongosql Transition Readiness Tool →

Other CWE-1236 (Improper Neutralization of Formula Elements in a CSV File) vulnerabilities

Browse all CWE-1236 (Improper Neutralization of Formula Elements in a CSV File) vulnerabilities →