Unvalidated Endpoint Vulnerability in MongoDB Products
CVE-2026-19503

6.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19503?

The vulnerability resides in MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver, where the validation of authorization and token endpoints of an OIDC issuer’s discovery document is inadequate. This flaw allows an attacker to exploit users connecting to potentially compromised MongoDB deployments through MONGODB-OIDC authentication. If a user is tricked into connecting, their system may process an uncontrolled URI that could lead to credential exposure or, under specific scenarios, result in code execution within the user's environment.

Affected Version(s)

Atlas SQL ODBC Driver 1.0.0 < 2.0.9

Schema Builder CLI 1.0.1 < 1.2.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.