Configuration Weakness in MongoDB Compass Affecting Connection Options
CVE-2026-14881
8.4HIGH
What is CVE-2026-14881?
A configuration weakness in MongoDB Compass allows users to override specific connection options during the import process. This oversight enables the provision of a custom browser open command for the OIDC authentication flow, a setting that typically can only be adjusted at a global level through Compass settings. This could lead to unintended behaviors in connection handling, potentially exposing sensitive data or altering user interactions within the application.
Affected Version(s)
MongoDB Compass 1.38.0 < 1.49.7