Injection Vulnerability in MongoDB Compass by MongoDB Inc.
CVE-2026-96750

7.3HIGH

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-96750?

MongoDB Compass exhibits an injection vulnerability that allows unescaped database names to be interpolated into the initial input of its embedded MongoDB shell. This occurs when users interact with the shell from the database's view. If a user has privileges to create databases on the server, they may inadvertently evaluate content as shell input within the Compass context. Such exposure can cause serious security risks, especially if sensitive data is mishandled or delivered through the compromised shell process.

Affected Version(s)

Compass 1.44.0 < 1.49.12

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.