MEDIUMVulnerability

CVE-2026-76797

The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.

Properties

severity
MEDIUM
score
6.3
cve_id
CVE-2026-76797
signal_observed_at
2026-09-17T21:31:49+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
published_at
2026-08-28T20:19:55.127
last_modified
2026-09-17T14:37:45.523

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Formula Elements in a CSV File

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76797 — Ninja Signal Threat Intelligence | Ninja Signal