An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9 | Release Notes Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-12 21:17
Updated : 2026-09-11 18:59
NVD link : CVE-2026-19004
Mitre link : CVE-2026-19004
CVE.ORG link : CVE-2026-19004
JSON object : View
Products Affected
mongodb
- bi_connector_odbc_driver
CWE
CWE-122
Heap-based Buffer Overflow
