High severity7.8NVD Advisory· Published Jul 22, 2026· Updated Jul 24, 2026
CVE-2026-14881
CVE-2026-14881
Description
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.