PT-2026-71305 · Mongodb · Mongodb Schema Manager+1
CVE-2026-19503
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MongoDB Schema Manager (affected versions not specified)
MongoDB Atlas SQL ODBC Driver (affected versions not specified)
Description
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver fail to validate the scheme of the authorization and token endpoints provided in an OIDC (OpenID Connect) issuer's discovery document. If a user is induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication, an uncontrolled URI may be dispatched to the operating system's default protocol handler. This could lead to the exposure of credentials or, in certain scenarios, result in code execution within the user's context.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Atlas Sql Odbc Driver
Mongodb Schema Manager