{"id":"CVE-2026-14881","title":"When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form","summary":"When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow th…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"mongodb","product":"compass","affected":["compass >= 1.38.0, < 1.49.7"],"patched":["compass 1.49.7"],"published":"2026-07-22","updated":"2026-09-30","sourceUpdated":"2026-09-30T13:16:34.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14881","references":[{"url":"https://github.com/mongodb-js/compass/releases/tag/v1.49.7","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.00194,"epssPercentile":0.0817,"ingestedAt":"2026-09-30T14:05:17.337Z","slug":"CVE-2026-14881","body":"## Overview\n\nWhen importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.\n\n## Affected\n\n- `compass >= 1.38.0, < 1.49.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `compass 1.49.7`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}