Junglewise Threat Intelligence

CVE-2026-76794: MongoDB MongoSQL Transition Readiness Tool XSS in HTML report generation

CVE-2026-76794 · Severity: medium · CVSS 4.6 · Published 2026-08-28

Technologies: MongoDB Mongosql Transition Readiness Tool. Vendors: MongoDB.

Executive brief

MongoDB's MongoSQL Transition Readiness Tool is a utility used to help organizations assess readiness for migrating from SQL systems to MongoDB's SQL interface. The tool generates HTML reports that can be shared among team members. A MongoDB user with write access can inject malicious script code into database metadata, which executes when another user opens the generated report, potentially exposing sensitive report contents or modifying how the report appears.

Technical details

This is a cross-site scripting (XSS) vulnerability in the MongoSQL Transition Readiness Tool's HTML report generation feature. The vulnerability occurs because the tool does not adequately HTML-encode database metadata before embedding it into generated HTML reports. An attacker with database write access can craft metadata containing JavaScript code; when a victim generates and opens the report in a web browser, the unencoded payload executes in the victim's context. This allows the attacker to exfiltrate report contents, manipulate the report display, or potentially perform other malicious actions. The attack requires both attacker write access to the database and victim interaction (opening the report).

Affected products

  • MongoDB MongoSQL Transition Readiness Tool <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References

Related threats