Junglewise Threat Intelligence

CVE-2026-18888: MongoDB BI Connector ODBC Driver buffer overflow in float-to-text conversion

CVE-2026-18888 · Severity: medium · CVSS 6.5 · Published 2026-08-12

Technologies: MongoDB Bi Connector Odbc Driver. Vendors: MongoDB.

Executive brief

The MongoDB BI Connector ODBC Driver, used to query MongoDB databases from BI tools and applications, does not properly validate the size of floating-point numbers when converting them to text. An attacker who can insert data into a collection could store a specially crafted large floating-point value that, when read through the connector, causes the driver to write beyond allocated memory and crash the reading application.

Technical details

The vulnerability is a classic buffer overflow in the ODBC driver's floating-point to text conversion logic. The driver converts floating point values without bounds-checking, allowing large values to overflow the destination buffer and corrupt adjacent memory. The attack requires the ability to store malicious data in a MongoDB collection that is then queried through the BI Connector; network-based remote exploitation is not direct, but depends on application context. An attacker with write access to MongoDB can reliably crash consuming applications, leading to denial of service. A patch was released in version 1.4.9 that clamps large floats during string conversion.

Affected products

  • MongoDB BI Connector ODBC Driver before 1.4.9

Timeline

  • 2026-08-12: disclosed
  • 2026-08-06: patched: Version 1.4.9 released

References

Related threats