CVE-2026-19503

Source
https://cve.org/CVERecord?id=CVE-2026-19503
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19503.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19503
Downstream
Published
2026-08-12T20:17:55Z
Modified
2026-10-01T03:47:47Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Insufficient OIDC endpoint validation could invoke unintended local protocol handlers
Details

MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.

Database specific
{
    "cna_assigner": "mongodb",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19503.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "fixed": "2.0.9"
                },
                {
                    "introduced": "1.0.1"
                },
                {
                    "fixed": "1.2.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo-odbc-driver

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-odbc-driver
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mongodb:odbc_driver:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "2.0.9"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

Other
another_test
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.4.0
v1.4.1
v1.4.5
v1.4.6
v2.*
v2.0.0
v2.0.0-alpha-libv1.0.0-alpha
v2.0.0-alpha-libv1.0.0-alpha-1
v2.0.0-beta-1-libv1.0.0-beta-2
v2.0.0-beta-2-libv1.0.0-beta-3
v2.0.0-beta-3-libv1.0.0-beta-4
v2.0.0-beta-4-libv1.0.0-beta-5
v2.0.0-beta-5-libv-1.0.0-beta-6
v2.0.0-beta-6-libv1.0.0-beta-6
v2.0.0-beta-libv1.0.0-beta-1
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19503.json"