---
id: CVE-2026-19503
title: >-
  MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the
  scheme of the authorization and token endpoints returned by an OIDC issuer's
  discovery document
summary: >-
  MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the
  scheme of the authorization and token endpoints returned by an OIDC issuer's
  discovery document. A user induced to connect to an uncontrolled MongoDB
  deployment…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-20
vendor: mongodb
product: odbc_driver
affected:
  - 'odbc_driver >= 1.0.0, < 2.0.9'
  - 'sql_schema_builder_cli >= 1.0.1, < 1.2.1'
patched:
  - odbc_driver 2.0.9
  - sql_schema_builder_cli 1.2.1
published: '2026-08-12'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:02:11.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19503'
references:
  - url: 'https://www.mongodb.com/docs/sql-interface/changelog'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.0021
epssPercentile: 0.1012
ingestedAt: '2026-09-29T21:49:08.165Z'
---

## Overview

MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.

## Affected

- `odbc_driver >= 1.0.0, < 2.0.9`
- `sql_schema_builder_cli >= 1.0.1, < 1.2.1`

## Remediation

Upgrade past the affected range:

- `odbc_driver 2.0.9`
- `sql_schema_builder_cli 1.2.1`
