Junglewise Threat Intelligence

CVE-2026-81532: MongoDB Connector for BI ODBC driver buffer overflow in cursor name handling

CVE-2026-81532 · Severity: high · CVSS 8.8 · Published 2026-08-28

Technologies: MongoDB Bi Connector Odbc Driver. Vendors: MongoDB.

Executive brief

The MongoDB Connector for BI ODBC driver is used to enable SQL-based access to MongoDB databases from business intelligence and reporting tools. An attacker who can submit SQL queries can cause a buffer overflow by specifying an overly long cursor name, which can crash the application or potentially execute arbitrary code within the host application's process.

Technical details

This is a classic stack-based buffer overflow vulnerability in the MongoDB Connector for BI ODBC driver. The vulnerable code fails to validate the length of a cursor name in a positioned-cursor SQL statement before copying it into a fixed-length internal buffer when building a diagnostic message. An attacker with the ability to submit SQL queries to an application using this driver can trigger the overflow by providing a cursor name that exceeds the buffer's capacity, overwriting adjacent memory with attacker-controlled data. The impact ranges from denial of service (application crash) to remote code execution. The vulnerability was patched in version 1.4.10 by adding logic to truncate cursor names to fit within the buffer.

Affected products

  • MongoDB Connector for BI ODBC driver before 1.4.10

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Version 1.4.10 released with cursor name truncation logic

References

Related threats