CVE-2026-14881

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-22 20:16

Updated : 2026-07-24 05:16


NVD link : CVE-2026-14881

Mitre link : CVE-2026-14881

CVE.ORG link : CVE-2026-14881


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')