Executive brief
MongoDB's Schema Manager and Atlas SQL ODBC Driver fail to validate the URI scheme of OIDC authentication endpoints, allowing an attacker to redirect users to arbitrary protocol handlers. This could expose authentication credentials or, in certain scenarios, lead to arbitrary code execution when a user connects to a malicious MongoDB deployment using OIDC authentication.
Technical details
MongoDB Schema Manager and the MongoDB Atlas SQL ODBC Driver do not properly validate the scheme (http, https, file, etc.) of authorization and token endpoints returned by an OIDC issuer's discovery document. An attacker controlling a malicious MongoDB deployment can serve a crafted OIDC discovery document with authorization or token endpoint URIs using non-https schemes (e.g., file://, custom protocol handlers). When a user connects using MONGODB-OIDC authentication, the client dispatches the unvalidated URI to the operating system's default protocol handler, potentially leading to credential exposure or code execution. The attack requires user interaction (connecting to an uncontrolled deployment) and network-level access to perform OIDC discovery spoofing.
Affected products
- MongoDB Schema Manager <UNKNOWN>
- MongoDB Atlas SQL ODBC Driver <UNKNOWN>
Timeline
- 2026-08-12: disclosed