CVE-2026-76797: MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated Reports

Published Aug 28, 2026
·
Updated

The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required.

Event History

Aug 28, 2026
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs write privileges on the MongoDB cluster so they can create or rename a database or collection namespace containing spreadsheet formula characters. They also need an operator to generate a report covering that namespace and open the CSV in a spreadsheet application.

2

Is opening the generated CSV required for impact?

Yes. The attacker-controlled namespace is written to the CSV report, but the formula is evaluated only when an operator opens that report in a spreadsheet application.

3

What is the practical impact on an affected operator?

A spreadsheet application may evaluate the injected formula, potentially disclosing report contents or executing external content on the operator's workstation. The issue does not require direct access to the operator's workstation before the report is opened.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203