Out-of-Bounds Write Vulnerability in MongoDB BI Connector ODBC Driver
CVE-2026-19002
8.8HIGH
What is CVE-2026-19002?
The MongoDB BI Connector ODBC Driver has a vulnerability due to a missing bounds check when parsing stored procedure parameter metadata. This flaw can lead to an out-of-bounds write within the client application process. To exploit this vulnerability, an attacker must have control over the server to which the driver connects, or the ability to return malformed metadata in response. The exploitation may result in memory corruption, which can lead to abnormal termination of the client application or the execution of unintended code under specific conditions.
Affected Version(s)
BI Connector ODBC Driver 1.0.0 < 1.4.9