Junglewise Threat Intelligence

CVE-2026-77586: MongoDB Connector for BI SQL injection via unescaped identifiers

CVE-2026-77586 · Severity: high · CVSS 8 · Published 2026-08-28

Technologies: MongoDB Connector for BI. Vendors: MongoDB.

Executive brief

MongoDB Connector for BI is a tool that allows SQL clients to query MongoDB databases. A vulnerability allows an attacker with write access to MongoDB collections to inject arbitrary SQL code into DDL statements. When these statements are executed against a SQL server by operators or automated tools, the injected code runs with the privileges of that session, potentially leading to unauthorized data access or modification.

Technical details

This is a SQL injection vulnerability in the DDL generation layer of MongoDB Connector for BI. MongoDB object names (collections, fields, indexes) are embedded into quoted identifiers in SHOW CREATE statements without proper escaping of the identifier delimiter. An attacker with write permissions to a MongoDB collection can craft a name containing quotes or other delimiter characters that closes the quoted identifier early, allowing additional SQL syntax to be injected into the generated statement. The vulnerability is triggered when an operator or automated tool replays the generated DDL against a SQL server; the injected SQL executes with the session's privileges. No authentication is required beyond existing MongoDB write access.

Affected products

  • MongoDB Connector for BI

Timeline

  • 2026-08-28: disclosed

References

Related threats