CVE-2026-96750

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.1
HIGH

Description

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.

Published
September 24, 2026 4:17 PM
Last Modified
September 24, 2026 6:19 PM
Source
[email protected]

Weaknesses (CWE)

CWE-94

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.