Junglewise Threat Intelligence

CVE-2026-19001: MongoDB BI Connector ODBC Driver buffer overflow in metadata functions

CVE-2026-19001 · Severity: critical · CVSS 9.8 · Published 2026-08-12

Technologies: MongoDB Bi Connector Odbc Driver. Vendors: MongoDB.

Executive brief

The MongoDB BI Connector ODBC Driver contains a buffer overflow vulnerability in its metadata retrieval functions. When an application requests metadata using unusually long catalog, schema, or object names, the driver writes beyond the bounds of its internal buffer. This can corrupt the calling application's memory, crash it, or potentially allow attackers to execute arbitrary code within the application's process context.

Technical details

The vulnerability is a classic stack or heap-based buffer overflow in the MongoDB BI Connector ODBC Driver's metadata retrieval functions. The root cause is insufficient bounds checking when processing catalog, schema, or object name parameters supplied by client applications. An attacker can trigger this by connecting through an ODBC client and supplying crafted metadata queries with excessively long name strings, requiring no authentication bypass. Successful exploitation results in memory corruption, leading to application crashes or, under specific conditions and memory layout, arbitrary code execution within the calling application's address space. Patch v1.4.9 (released August 6, 2026) includes clamping logic to enforce maximum name lengths.

Affected products

  • MongoDB BI Connector ODBC Driver before v1.4.9

Timeline

  • 2026-08-12: disclosed
  • 2026-08-06: patched: v1.4.9 released with clamping logic for name lengths

References

Related threats