PatchSiren cyber security CVE debrief
CVE-2026-77184 MongoDB CVE debrief
CVE-2026-77184 debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T20:19:55.400Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders and operators of MongoDB BI Connector deployments, especially those using SQL schema generation from collection validators, should assess exposure and prioritize verification. The vulnerability allows users with schema validator modification permissions to embed additional SQL text, potentially leading to SQL injection risks.
- Vendor
- MongoDB
- Product
- BI Connector
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-29
Who should care
Defenders and operators of MongoDB BI Connector deployments, especially those using SQL schema generation from collection validators, should assess exposure and prioritize verification.
Why it matters
CVE-2026-77184 is a medium-severity vulnerability in MongoDB BI Connector that allows users with schema validator modification permissions to embed additional SQL text. Defenders should assess exposure, verify versions, and consider compensating controls.
- Potential SQL injection risk through crafted schema validator descriptions.
- Possible execution of additional SQL text with elevated privileges.
- Need for verification of affected versions and configurations.
- Importance of monitoring and restricting SQL execution.
Technical summary
The MongoDB BI Connector's JSON schema validator description text is not properly escaped, allowing a user with permission to modify a collection's schema validator to embed additional SQL text. This additional text can be executed with the privileges of the session replaying the generated SQL statement. The vulnerability affects MongoDB BI Connector deployments using SQL schema generation from collection validators, requiring verification of affected versions and configurations to mitigate potential SQL injection risks.
Defensive priority
Defenders should assess exposure and prioritize verification of MongoDB BI Connector deployments, especially those using SQL schema generation from collection validators.
Recommended defensive actions
- Review MongoDB BI Connector deployments for exposure, especially those using SQL schema generation from collection validators.
- Verify the version of MongoDB BI Connector is not earlier than 2.1.0 and not later than 2.14.31.
- Assess the privileges of sessions that replay generated SQL statements.
- Consider implementing compensating controls to monitor and restrict SQL execution.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE description indicates that MongoDB BI Connector's JSON schema validator description text is not properly escaped, allowing additional SQL text to be embedded. This requires verification of affected versions and configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77184 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77184
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77184 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77184
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.mongodb.com/docs/bi-connector/current/release-notes/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.