๐Ÿ” CVE Alert

CVE-2026-14881

HIGH 7.8

Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.

CWE CWE-78
Vendor mongodb
Product mongodb compass
Ecosystems
Industries
Technology
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb mongodb compass

Be the first to know when new high vulnerabilities affecting mongodb mongodb compass are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

MongoDB / MongoDB Compass
1.38.0 < 1.49.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mongodb-js/compass/releases/tag/v1.49.7