CVE-2026-14881
Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.
| CWE | CWE-78 |
| Vendor | mongodb |
| Product | mongodb compass |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for mongodb mongodb compass
Be the first to know when new high vulnerabilities affecting mongodb mongodb compass are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
MongoDB / MongoDB Compass
1.38.0 < 1.49.7