Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96750— Shell script injection via server-supplied database name in Open MongoDB shell

Quick assessment

Affected
MongoDB Compass
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoDB Compass 在用户从其数据库视图打开嵌入式的 MongoDB Shell 时,会对数据库名称进行插值处理而未进行适当的转义,从而将其插入到 Shell 的初始输入中。如果某用户在 Compass 所连接的目标服务器上具有创建数据库的权限,则在特定条件下,该用户可能使其构造的内容被作为 Shell 输入在 Compass 进程内执行,并继承该进程的权限。此漏洞利用要求 Compass 用户打开受影响数据库对应的 Shell。

CVSS 7.1 · High EPSS 0.19% · P7
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96750

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Shell script injection via server-supplied database name in Open MongoDB shell
Source: CVE Program / CVE List V5
Vulnerability Description
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB Compass 1.44.0 ~ 1.49.12 -

II. Public POCs for CVE-2026-96750

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96750

请登录查看更多情报信息。

Other References for CVE-2026-96750 (1)

Same Patch Batch · MongoDB · 2026-09-24 · 7 CVEs total

CVE-2026-96749 8.4 HIGH Heap out-of-bounds write via signed size overflow in BSON document encoding
CVE-2026-96744 7.1 HIGH Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB
CVE-2026-96746 6.5 MEDIUM Heap buffer overflow via mid-scan command list growth in client topology monitoring
CVE-2026-96748 6.5 MEDIUM Connection redirection via percent-encoded delimiter injection in connection string hosts
CVE-2026-96745 5.6 MEDIUM PHP object injection via unsuppressible __pclass class inference in command monitoring eve
CVE-2026-96747 5.0 MEDIUM Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt

IV. Related Vulnerabilities

V. Comments for CVE-2026-96750

No comments yet


Leave a comment