MongoDBCVE-2026-19503
MongoDB Atlas SQL ODBC Driver: code execution
Medium6.3CVE-2026-19503 · Published Aug 12, 2026 · updated Aug 28, 2026
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Atlas SQL ODBC Driver Product | >= 1.0.0, < 2.0.9 | 2.0.9 |
| Schema Builder CLI Product | >= 1.0.1, < 1.2.1 | 1.2.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | MongoDB BI Connector ODBC Driver: stack buffer overflow | High8.4 | 1.4.9 |
| Aug 12 | MongoDB Schema Builder CLI: secrets in logs | Medium6.8 | 1.2.1 |
| Aug 12 | MongoDB BI Connector ODBC Driver: out-of-bounds write | High7.1 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: memory corruption | Critical9.5 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: out-of-bounds write | High8.8 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: code execution | High8.8 | 1.4.9 |