CVE-2026-96750 is a vulnerability in MongoDB Compass
Published on September 24, 2026
Shell script injection via server-supplied database name in Open MongoDB shell
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.
Vulnerability Analysis
CVE-2026-96750 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2026-96750 has been classified to as a Code Injection vulnerability or weakness.
Products Associated with CVE-2026-96750
Want to know whenever a new CVE is published for MongoDB Compass? stack.watch will email you.
Affected Versions
MongoDB Compass:- Version 1.44.0 and below 1.49.12 is affected.