云虫漏洞库

CVE-2026-77586 - In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes the quoted identifier early, so that additional SQL text becomes part of the generated output. If an operator or automated tool later replays that generated statem - 漏洞详情

漏洞编号:CVE-2026-77586

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-77586

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-89

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes the quoted identifier early, so that additional SQL text becomes part of the generated output. If an operator or automated tool later replays that generated statement against a SQL server, the additional text is executed with the privileges of that session.

相关链接

相关漏洞

« 返回首页