Vulnerability Description
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Bi Connector Odbc Driver | >= 1.0.0, < 1.4.9 |
Related Weaknesses (CWE)
References
- https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9Vendor AdvisoryRelease Notes
FAQ
What is CVE-2026-19001?
CVE-2026-19001 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function...
How severe is CVE-2026-19001?
CVE-2026-19001 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-19001?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Bi Connector Odbc Driver.