CVE-2026-19001Patch(mongodb / bi_connector_odbc_driver)

LOWCVSS 9.5 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mongodb bi_connector_odbc_driver systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bi_connector_odbc_driver

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-18); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
bi_connector_odbc_driver

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-08-13: 1Mentions · 2026-08-18: 3Mentions · 2026-08-19: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-18: 2Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-18: 3Technical Details · 2026-08-19: 108-1308-1808-19
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-131
Patch1
2026-08-183
Disclosure1Patch2
2026-08-191
Patch1
Full discourse5 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: MongoDB has patched 32 security vulnerabilities, led by CVE-2026-19001 with a CVSS 9.5 score. The flaw affects the BI Connector ODBC Driver and can allow attackers to achieve arbitrary code execution. Administrators should review MongoDB’s security updates and patch affected deployments immediately. #MongoDB #CVE #RCE #CyberSecurity #DatabaseSecurity #Infosec

    Post summary

    MongoDB issued patches for 32 vulnerabilities, including CVE-2026-19001 (CVSS 9.5), which allows arbitrary code execution via the BI Connector ODBC Driver; administrators are urged to apply updates immediately.

    02090791
    1.6K followersView on X
  • yousukezan@yousukezan
    Patch

    MongoDBは、ServerやODBC Driverなど4製品に計32件の脆弱性を公開した。最も深刻なCVE-2026-19001では、BI Connector ODBC Driverのメモリ破壊を通じて任意コード実行につながる可能性がある。 CVE-2026-19001は、巨大なカタログオブジェクト名の処理で確保済みバッファの外へ書き込む問題で、BI Connector ODBC Driver 1.4.9で修正された。同ドライバではCVE-2026-19002やCVE-2026-19004など複数のメモリ破壊問題も修正された。MongoDB Serverでは、クラスタ内接続の不適切な認証による認証情報露出のCVE-2026-18691、時系列バケット処理のUse-After-FreeでDoSやコード実行につながる可能性があるCVE-2026-18692などを修正した。修正版はServer 7.0.40、8.0.29、8.3.8、Atlas SQL ODBC Driver 2.0.9、Schema Builder CLI 1.2.1。記事執筆時点で32件の悪用は確認されていない。 https://securityonline.info/mongodb-vulnerabilities-cve-2026-19001/

    Post summary

    MongoDB released patches for 32 vulnerabilities, including CVE‑2026‑19001 that could enable code execution, with no active exploitation reported.

    110111.2K
    14.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - MongoDB BI Connector ODBC Driver Buffer Overflow (CVE-2026-19001) The MongoDB BI Connector ODBC Driver before 1.4.9 writes outside a fixed-size buffer when an application passes an unusually long catalog, schema, or object name to a metadata-retrieval function. This corrupts memory in the calling application's process, causing crashes and, under certain conditions, potentially arbitrary code execution. This is a client-side flaw affecting the BI or analytics application using the driver, not the MongoDB server. Real risk is highest where the catalog/schema/object name can be attacker-influenced. MongoDB rates it CVSS 9.8 (v3.1) / 9.5 (v4). 👉Upgrade the MongoDB BI Connector ODBC Driver to 1.4.9.

    Post summary

    The post discloses a critical buffer‑overflow flaw in the MongoDB BI Connector ODBC Driver and advises users to upgrade to version 1.4.9 to mitigate the risk.

    00010114
    288 followersView on X
  • キタきつね@foxbook
    Patch

    MongoDBが32件の脆弱性を修正、CVE-2026-19001(任意コード実行の脆弱性、CVSS 9.5)を含む MongoDB Patches 32 Vulnerabilities, Including CVE-2026-19001 Arbitrary Code Execution Flaw (CVSS 9.5) #DailyCyberSecurity (Aug 18) https://securityonline.info/mongodb-vulnerabilities-cve-2026-19001/

    Post summary

    MongoDB released security patches for 32 vulnerabilities, including CVE-2026-19001, an arbitrary code execution flaw with a CVSS score of 9.5.

    00000283
    4.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-19001 (CVSS 9.5) headlines 32 MongoDB security vulnerabilities, including a BI Connector ODBC Driver flaw enabling arbitrary code execution. #MongoDB #CVE202619001 #BIConnector #InfoSec https://securityonline.info/mongodb-vulnerabilities-cve-2026-19001/

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑19001) in MongoDB’s BI Connector ODBC Driver that allows arbitrary code execution, but no proof of concept or exploit details are provided.

    00000392
    12.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbbi_connector_odbc_driver---

Explore more