CVE-2026-19004: MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19004?
The severity of CVE-2026-19004 is high, rated at 8.1.
How do I fix CVE-2026-19004?
To fix CVE-2026-19004, you should update to the latest version of the MongoDB BI Connector ODBC driver.
What is the impact of CVE-2026-19004 on my application?
CVE-2026-19004 can cause a memory-safety issue which might lead to unpredictable behavior or crashes of applications using the affected driver.
Who is affected by CVE-2026-19004?
Any application that employs the MongoDB BI Connector ODBC driver and connects to untrusted database servers may be affected by CVE-2026-19004.
What kind of issue does CVE-2026-19004 involve?
CVE-2026-19004 involves a memory-safety issue related to processing output parameters from stored procedures.