Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog/ |
|
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required. | |
| Title | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated Reports | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-28T19:24:07.640Z
Reserved: 2026-08-19T19:14:12.273Z
Link: CVE-2026-76797
No data.
Status : Awaiting Analysis
Published: 2026-08-28T20:19:55.127
Modified: 2026-08-28T21:16:15.740
Link: CVE-2026-76797
No data.
OpenCVE Enrichment
No data.
-
CWE-1236
Improper Neutralization of Formula Elements in a CSV File