nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-19503 CVE-2026-19503
MEDIUM
Insufficient OIDC endpoint validation could invoke unintended local protocol handlers
Record summary
CVE-2026-19503 has a selected CVSS score of 6.3 (medium).
Description
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Atlas SQL ODBC DriverBrowse MongoDB / Atlas SQL ODBC DriverDefault status: unaffected | CVE List | 1.0.0 to < 2.0.9 | affected |
Schema Builder CLIBrowse MongoDB / Schema Builder CLIDefault status: unaffected | CVE List | 1.0.1 to < 1.2.1 | affected |
References
2mongodb.com
https://www.mongodb.com/docs/sql-interface/changelog