What is CVE-2026-14881?
CVE-2026-14881 is a vulnerability in MongoDB Compass that allows overriding connection options during import, such as providing a custom browser open command for OIDC authentication flow, which is typically restricted to global settings. This could lead to unauthorized manipulation of sensitive configurations. Users should update Compass to the latest version and carefully review imported connection files.
Azərbaycanca: CVE-2026-14881, MongoDB Compass-də əlaqə idxalı zamanı OIDC autentifikasiya axını üçün fərdi brauzer açma əmri kimi bağlantı seçimlərinin lazımsız yerə dəyişdirilməsinə imkan verən zəiflikdir. Bu, normalda yalnız qlobal parametrlərlə məhdudlaşdırılan həssas konfiqurasiyaların istismarına səbəb ola bilər. İstifadəçilər Compass-i ən son versiyaya yeniləməli və idxal edilən əlaqə fayllarını diqqətlə yoxlamalıdır.
FAQ2
Which functionality of MongoDB Compass is affected by CVE-2026-14881?
This vulnerability affects the connection import feature in MongoDB Compass, allowing override of connection options such as providing a custom browser open command for the OIDC authentication flow, which can lead to unauthorized manipulation of sensitive configurations.
What should users do to protect against CVE-2026-14881?
Users should update MongoDB Compass to the latest version and carefully review imported connection files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.