Answer in brief
CVE-2026-19503 records a Unknown severity vulnerability in Insufficient OIDC endpoint validation could invoke unintended local protocol handlers. The current sources do not mark it as known exploited. The current feed maps MongoDB/Atlas SQL ODBC Driver (generic), MongoDB/Schema Builder CLI (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps MongoDB/Atlas SQL ODBC Driver (generic), MongoDB/Schema Builder CLI (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| MongoDB/Atlas SQL ODBC Drivergeneric | >=1.0.0 <2.0.9 | 2.0.9 |
| MongoDB/Schema Builder CLIgeneric | >=1.0.1 <1.2.1 | 1.2.1 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-19503 records a Unknown severity vulnerability in Insufficient OIDC endpoint validation could invoke unintended local protocol handlers. The current sources do not mark it as known exploited. The current feed maps MongoDB/Atlas SQL ODBC Driver (generic), MongoDB/Schema Builder CLI (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps MongoDB/Atlas SQL ODBC Driver (generic), MongoDB/Schema Builder CLI (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| MongoDB/Atlas SQL ODBC Drivergeneric | >=1.0.0 <2.0.9 | 2.0.9 |
| MongoDB/Schema Builder CLIgeneric | >=1.0.1 <1.2.1 | 1.2.1 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context.
Quoted source text, attributed separately from HOL analysis.