CVE-2026-14881

HIGH

MongoDB Compass < 1.49.7 - OIDC Browser Command Injection

Title source: manual
STIX 2.1

Description

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
MongoDB/MongoDB Compass 1.38.0 - 1.49.7
Published Jul 22, 2026
Tracked Since Jul 23, 2026