MEDIUMVulnerability
CVE-2026-76797
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.
Properties
- severity
- MEDIUM
- score
- 6.3
- cve_id
- CVE-2026-76797
- signal_observed_at
- 2026-09-17T21:31:49+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
- published_at
- 2026-08-28T20:19:55.127
- last_modified
- 2026-09-17T14:37:45.523
Related Entities (3)
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Formula Elements in a CSV File
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph