mongodb compass CVE-2026-96750 is a vulnerability in MongoDB Compass
Published on September 24, 2026

Shell script injection via server-supplied database name in Open MongoDB shell
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.

NVD

Vulnerability Analysis

CVE-2026-96750 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
ACTIVE

Weakness Type

What is a Code Injection Vulnerability?

The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE-2026-96750 has been classified to as a Code Injection vulnerability or weakness.


Products Associated with CVE-2026-96750

Want to know whenever a new CVE is published for MongoDB Compass? stack.watch will email you.

 

Affected Versions

MongoDB Compass: