Memory-Safety Issue in MongoDB BI Connector ODBC Driver
CVE-2026-19004

8.8HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19004?

An application utilizing the MongoDB BI Connector ODBC Driver may encounter a memory-safety vulnerability when handling output parameters from stored procedures. This vulnerability can be exploited if an application connects to an untrusted or impersonated database server capable of delivering malformed metadata. Successful exploitation may lead to process termination, unintended disclosure of process memory, or in certain scenarios, allow for arbitrary code execution.

Affected Version(s)

BI Connector ODBC Driver 1.0.0 < 1.4.9

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.