MongoDBCVE-2026-18888
MongoDB BI Connector ODBC Driver: out-of-bounds write
High7.1CVE-2026-18888 · Published Aug 12, 2026 · updated Sep 11, 2026
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| BI Connector ODBC Driver Product | >= 1.0.0, < 1.4.9 | 1.4.9 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-787
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | MongoDB BI Connector ODBC Driver: stack buffer overflow | High8.4 | 1.4.9 |
| Aug 12 | MongoDB Schema Builder CLI: secrets in logs | Medium6.8 | 1.2.1 |
| Aug 12 | MongoDB Atlas SQL ODBC Driver: code execution | Medium6.3 | 2.0.9+1 more |
| Aug 12 | MongoDB BI Connector ODBC Driver: memory corruption | Critical9.5 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: out-of-bounds write | High8.8 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: code execution | High8.8 | 1.4.9 |