CVE-2026-19001: MongoDB BI Connector Odbc Driver

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.

Affected products

  • MongoDB BI Connector Odbc Driver: from 1.0.0, before 1.4.9 (fixed in 1.4.9)

Published 2026-08-12. Last modified 2026-09-11.