github.com
https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9 CVE-2026-19002
HIGH
Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver
Record summary
CVE-2026-19002 has a selected CVSS score of 8.8 (high).
Description
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BI Connector ODBC DriverBrowse MongoDB / BI Connector ODBC DriverDefault status: unaffected | CVE List | 1.0.0 to < 1.4.9 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-19002