PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77184 MongoDB CVE debrief

CVE-2026-77184 debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T20:19:55.400Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders and operators of MongoDB BI Connector deployments, especially those using SQL schema generation from collection validators, should assess exposure and prioritize verification. The vulnerability allows users with schema validator modification permissions to embed additional SQL text, potentially leading to SQL injection risks.

Vendor
MongoDB
Product
BI Connector
CVSS
MEDIUM 5.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-09-29
Advisory published
2026-08-28
Advisory updated
2026-09-29

Who should care

Defenders and operators of MongoDB BI Connector deployments, especially those using SQL schema generation from collection validators, should assess exposure and prioritize verification.

Why it matters

CVE-2026-77184 is a medium-severity vulnerability in MongoDB BI Connector that allows users with schema validator modification permissions to embed additional SQL text. Defenders should assess exposure, verify versions, and consider compensating controls.

  • Potential SQL injection risk through crafted schema validator descriptions.
  • Possible execution of additional SQL text with elevated privileges.
  • Need for verification of affected versions and configurations.
  • Importance of monitoring and restricting SQL execution.

Technical summary

The MongoDB BI Connector's JSON schema validator description text is not properly escaped, allowing a user with permission to modify a collection's schema validator to embed additional SQL text. This additional text can be executed with the privileges of the session replaying the generated SQL statement. The vulnerability affects MongoDB BI Connector deployments using SQL schema generation from collection validators, requiring verification of affected versions and configurations to mitigate potential SQL injection risks.

Defensive priority

Defenders should assess exposure and prioritize verification of MongoDB BI Connector deployments, especially those using SQL schema generation from collection validators.

Recommended defensive actions

  • Review MongoDB BI Connector deployments for exposure, especially those using SQL schema generation from collection validators.
  • Verify the version of MongoDB BI Connector is not earlier than 2.1.0 and not later than 2.14.31.
  • Assess the privileges of sessions that replay generated SQL statements.
  • Consider implementing compensating controls to monitor and restrict SQL execution.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE description indicates that MongoDB BI Connector's JSON schema validator description text is not properly escaped, allowing additional SQL text to be embedded. This requires verification of affected versions and configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77184 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77184

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77184 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77184

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.