Metrics
Affected Vendors & Products
| Link | Providers |
|---|---|
| https://www.mongodb.com/docs/sql-interface/changelog |
|
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb atlas Sql Odbc Driver Mongodb schema Builder Cli |
|
| Vendors & Products |
Mongodb
Mongodb atlas Sql Odbc Driver Mongodb schema Builder Cli |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context. | |
| Title | Insufficient OIDC endpoint validation could invoke unintended local protocol handlers | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-13T12:48:17.425Z
Reserved: 2026-08-10T18:59:54.023Z
Link: CVE-2026-19503
Updated: 2026-08-13T12:48:13.766Z
Status : Received
Published: 2026-08-12T21:17:38.383
Modified: 2026-08-13T13:17:48.993
Link: CVE-2026-19503
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:47:57Z