MongoDBCVE-2026-19004
MongoDB BI Connector ODBC Driver: code execution
High8.8CVE-2026-19004 · Published Aug 12, 2026 · updated Sep 11, 2026
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| BI Connector ODBC Driver Product | >= 1.0.0, < 1.4.9 | 1.4.9 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-122
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | MongoDB BI Connector ODBC Driver: stack buffer overflow | High8.4 | 1.4.9 |
| Aug 12 | MongoDB Schema Builder CLI: secrets in logs | Medium6.8 | 1.2.1 |
| Aug 12 | MongoDB Atlas SQL ODBC Driver: code execution | Medium6.3 | 2.0.9+1 more |
| Aug 12 | MongoDB BI Connector ODBC Driver: out-of-bounds write | High7.1 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: memory corruption | Critical9.5 | 1.4.9 |
| Aug 12 | MongoDB BI Connector ODBC Driver: out-of-bounds write | High8.8 | 1.4.9 |