Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-19001: MongoDB BI Connector ODBC driver may cause data corruption or crashes

CVE-2026-19001 · published 22 days ago
Summary

A security flaw in the MongoDB BI Connector ODBC driver could cause the program using it to crash or behave unexpectedly. This is because the driver doesn't handle very long names properly, which can lead to data corruption or even allow attackers to run malicious code. To stay safe, update the ODBC driver to the latest version as soon as possible.

What to do
  • Update mongodb bi connector odbc driver to version 1.4.9 or later.
Affected software
VendorProductAffected versions
mongodb bi connector odbc driver < 1.4.9
Original advisory text
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval funct...
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.
Severity
9.5 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Sources
CVE-2026-19001 · MITRE
Monitor software like this
Free during beta