CVE-2026-19001: MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19001?
The severity of CVE-2026-19001 is critical with a score of 9.8.
What vulnerabilities are associated with CVE-2026-19001?
CVE-2026-19001 is associated with the risk of memory corruption due to buffer overflow when handling oversized names in the MongoDB BI Connector ODBC driver.
How do I fix CVE-2026-19001?
To fix CVE-2026-19001, users should update to the latest version of the MongoDB BI Connector ODBC driver that addresses this vulnerability.
What impact does CVE-2026-19001 have on applications using MongoDB BI Connector?
CVE-2026-19001 may lead to memory corruption, causing applications using the MongoDB BI Connector to behave abnormally.
Which component is vulnerable in CVE-2026-19001?
The vulnerable component in CVE-2026-19001 is the MongoDB BI Connector ODBC driver.