Back to overview

CVE-2026-14881

HIGH
7.8
CVSS 3.1
Description
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.

Metadata

CVE ID
CVE-2026-14881
State
PUBLISHED
Assigner
mongodb
Reserved
2026-07-06 16:26 UTC
Published
2026-07-22 19:23 UTC
Last updated
2026-07-22 19:23 UTC
Primary CWE
CWE-78
CWE-78 Improper neutralization of special elements used in a…
Vendor / Product
MongoDB / MongoDB Compass
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
MongoDB MongoDB Compass 1.38.0 < 1.49.7
Weakness (CWE)
CWESourceDescription
CWE-78 cna CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.4 HIGH 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Back to overview