Buffer Overflow Vulnerability in MongoDB BI Connector ODBC Driver
CVE-2026-19003

8.4HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19003?

A vulnerability exists in the MongoDB BI Connector ODBC Driver due to a flaw in the buffer capacity calculation in the setup dialog. When a user opens the setup dialog for a data source with an excessively long file path, it could lead to a buffer overflow. This vulnerability can result in abnormal process termination, and under specific conditions, it may allow for unintended code execution within the context of the user operating the dialog. This issue highlights the risks associated with improper handling of user inputs in software configurations.

Affected Version(s)

BI Connector ODBC Driver Windows 1.0.0 < 1.4.9

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.