CVE-2026-14881: Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow
Published Jul 22, 2026
·Updated
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.
Affected Software
1 affected component
MongoDB Compass
Event History
Jul 22, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14881?
The severity of CVE-2026-14881 is high, with a CVSS score of 7.8.
2
How do I fix CVE-2026-14881?
To fix CVE-2026-14881, update MongoDB Compass to version 1.49.7 or later.
3
What is the impact of CVE-2026-14881?
CVE-2026-14881 allows arbitrary shell command execution through OIDC authentication, posing a significant security risk.
4
What vulnerability type is associated with CVE-2026-14881?
CVE-2026-14881 is categorized as an OS Command Injection vulnerability.
5
What is the nature of the exploit in CVE-2026-14881?
CVE-2026-14881 exploits the ability to override connection options during the OIDC authentication flow.