PT-2026-71305 · Mongodb · Mongodb Schema Manager+1

CVE-2026-19503

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MongoDB Schema Manager (affected versions not specified) MongoDB Atlas SQL ODBC Driver (affected versions not specified)
Description MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver fail to validate the scheme of the authorization and token endpoints provided in an OIDC (OpenID Connect) issuer's discovery document. If a user is induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication, an uncontrolled URI may be dispatched to the operating system's default protocol handler. This could lead to the exposure of credentials or, in certain scenarios, result in code execution within the user's context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19503

Affected Products

Mongodb Atlas Sql Odbc Driver
Mongodb Schema Manager