Out-of-Bounds Write Vulnerability in MongoDB BI Connector ODBC Driver
CVE-2026-19002

8.8HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19002?

The MongoDB BI Connector ODBC Driver has a vulnerability due to a missing bounds check when parsing stored procedure parameter metadata. This flaw can lead to an out-of-bounds write within the client application process. To exploit this vulnerability, an attacker must have control over the server to which the driver connects, or the ability to return malformed metadata in response. The exploitation may result in memory corruption, which can lead to abnormal termination of the client application or the execution of unintended code under specific conditions.

Affected Version(s)

BI Connector ODBC Driver 1.0.0 < 1.4.9

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.