CVE-2026-19004: MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters

Published Aug 12, 2026
·
Updated

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.

Affected Software

1 affected component
MongoDB BI Connector ODBC driver

Event History

Aug 12, 2026
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19004?

The severity of CVE-2026-19004 is high, rated at 8.1.

2

How do I fix CVE-2026-19004?

To fix CVE-2026-19004, you should update to the latest version of the MongoDB BI Connector ODBC driver.

3

What is the impact of CVE-2026-19004 on my application?

CVE-2026-19004 can cause a memory-safety issue which might lead to unpredictable behavior or crashes of applications using the affected driver.

4

Who is affected by CVE-2026-19004?

Any application that employs the MongoDB BI Connector ODBC driver and connects to untrusted database servers may be affected by CVE-2026-19004.

5

What kind of issue does CVE-2026-19004 involve?

CVE-2026-19004 involves a memory-safety issue related to processing output parameters from stored procedures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203