Skip to content
mongodbCVE-2026-96750

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view.

High7.3CVE-2026-96750 · Published Sep 24, 2026 · updated Sep 25, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Compass
Vendor
>= 1.44.0, < 1.49.121.49.12
Details and references

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.

CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
no source yet
Weakness
CWE-94

More mongodb advisories

All
DateAdvisory
Sep 24PHP object injection via unsuppressible __pclass class inference in command monitoring events
CVE-2026-96745Medium6.3fixed in 1.21.10, 2.1.10, 2.5.3
Sep 24Heap buffer overflow via mid-scan command list growth in client topology monitoring
CVE-2026-96746High8.3fixed in 1.30.12, 2.5.5
Sep 24Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as...
CVE-2026-96744High7.1fixed in Laravel MongoDB (PHP) 5.11.0
Sep 24PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
CVE-2026-96747Medium5.3fixed in 4.18.2
Sep 24PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
CVE-2026-96748High8.3fixed in 4.18.2
Sep 24PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
CVE-2026-96749High7.5fixed in 4.18.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.