CVE-2026-9101
CVE-2026-9101 is a medium-severity vulnerability in Mongodb Compass with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1321.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-31127
- Weakness: CWE-1321
- Affected product: Mongodb Compass
- Published:
- Last modified:
Description
Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.
Frequently asked questions
- What is CVE-2026-9101?
- Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.
- How severe is CVE-2026-9101?
- CVE-2026-9101 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-9101 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-9101?
- CVE-2026-9101 primarily affects Mongodb Compass. In total, 63 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-9101?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-9101 have an EU (EUVD) identifier?
- Yes. CVE-2026-9101 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-31127.
- When was CVE-2026-9101 published?
- CVE-2026-9101 was published on 2026-05-20 and last updated on 2026-09-24.
References
Affected products (63)
- cpe:2.3:a:mongodb:compass:1.36.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.36.4:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.37.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.38.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.38.1:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.38.2:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.39.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.39.1:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.39.2:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.39.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.39.4:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.40.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.40.1:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.40.2:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.40.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.40.4:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.41.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.42.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.42.1:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.42.2:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.42.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.42.5:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.1:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.2:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.4:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.5:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.43.6:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.44.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.44.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.44.4:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.44.5:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.44.6:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.44.7:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.45.0:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.45.1:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.45.2:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.45.3:*:*:*:*:*:*:*
- cpe:2.3:a:mongodb:compass:1.45.4:*:*:*:*:*:*:*
More vulnerabilities in Mongodb Compass
- CVE-2026-14881 — High (CVSS 7.8): When importing connections in Compass it is possible to override some connection options that are otherwise can't be…
- CVE-2025-1755 — High (CVSS 7.5): MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling…
- CVE-2024-3371 — High (CVSS 7.1): MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause…
- CVE-2024-6376 — High (CVSS 7.0): MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of…
- CVE-2021-20334 — Medium (CVSS 4.8): A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary…
All CVEs affecting Mongodb Compass →
Other CWE-1321 (Prototype Pollution) vulnerabilities
- CVE-2026-25142 — Critical (CVSS 10.0): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__…
- CVE-2024-39008 — Critical (CVSS 10.0): robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This…
- CVE-2024-38999 — Critical (CVSS 10.0): jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This…
- CVE-2022-29823 — Critical (CVSS 10.0): Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object.…
- CVE-2022-24760 — Critical (CVSS 10.0): Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution…
- CVE-2020-12079 — Critical (CVSS 10.0): Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron…