Executive brief
The MongoDB Connector for BI ODBC driver is used to enable SQL-based access to MongoDB databases from business intelligence and reporting tools. An attacker who can submit SQL queries can cause a buffer overflow by specifying an overly long cursor name, which can crash the application or potentially execute arbitrary code within the host application's process.
Technical details
This is a classic stack-based buffer overflow vulnerability in the MongoDB Connector for BI ODBC driver. The vulnerable code fails to validate the length of a cursor name in a positioned-cursor SQL statement before copying it into a fixed-length internal buffer when building a diagnostic message. An attacker with the ability to submit SQL queries to an application using this driver can trigger the overflow by providing a cursor name that exceeds the buffer's capacity, overwriting adjacent memory with attacker-controlled data. The impact ranges from denial of service (application crash) to remote code execution. The vulnerability was patched in version 1.4.10 by adding logic to truncate cursor names to fit within the buffer.
Affected products
- MongoDB Connector for BI ODBC driver before 1.4.10
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Version 1.4.10 released with cursor name truncation logic