CVE-2026-19002

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:bi_connector_odbc_driver:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 21:17

Updated : 2026-09-11 18:52


NVD link : CVE-2026-19002

Mitre link : CVE-2026-19002

CVE.ORG link : CVE-2026-19002


JSON object : View

Products Affected

mongodb

  • bi_connector_odbc_driver
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')