{"id":"CVE-2026-19503","title":"MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document","summary":"MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-20"],"vendor":"mongodb","product":"odbc_driver","affected":["odbc_driver >= 1.0.0, < 2.0.9","sql_schema_builder_cli >= 1.0.1, < 1.2.1"],"patched":["odbc_driver 2.0.9","sql_schema_builder_cli 1.2.1"],"published":"2026-08-12","updated":"2026-09-29","sourceUpdated":"2026-09-29T21:02:11.887","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19503","references":[{"url":"https://www.mongodb.com/docs/sql-interface/changelog","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.0021,"epssPercentile":0.1012,"ingestedAt":"2026-09-29T21:49:08.165Z","slug":"CVE-2026-19503","body":"## Overview\n\nMongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.\n\n## Affected\n\n- `odbc_driver >= 1.0.0, < 2.0.9`\n- `sql_schema_builder_cli >= 1.0.1, < 1.2.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `odbc_driver 2.0.9`\n- `sql_schema_builder_cli 1.2.1`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}