• PATCH AVAILABLE

CVE-2026-19001: buffer overflow in MongoDB BI Connector ODBC Driver

Remote attackers can cause memory corruption in the MongoDB BI Connector ODBC Driver and potentially execute code by supplying unusually long catalog, schema, or object names to a metadata retrieval function. CVE-2026-19001 affects versions 1.0.0 through 1.4.8; the issue is fixed in 1.4.9. Exploitation only requires the ability to invoke the affected metadata functions with overly long identifiers — no additional privileges or user interaction are required in the triggering call.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00539
CWE
CWE-190
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is exploitable without authentication or user interaction (CVSS vector shows AV:N/PR:N/UI:N); prioritize updating to 1.4.9 or apply mitigations immediately for exposed services.

What is CVE-2026-19001?

Remote attackers can cause memory corruption in the MongoDB BI Connector ODBC Driver and potentially execute code by supplying unusually long catalog, schema, or object names to a metadata retrieval function. CVE-2026-19001 affects versions 1.0.0 through 1.4.8; the issue is fixed in 1.4.9. Exploitation only requires the ability to invoke the affected metadata functions with overly long identifiers — no additional privileges or user interaction are required in the triggering call.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of MongoDB BI Connector ODBC Driver are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – before 1.4.91.4.9

Is CVE-2026-19001 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-19001

  1. Upgrade MongoDB BI Connector ODBC Driver to 1.4.9.
  2. If immediate upgrade is not possible, restrict access to services that can invoke the driver’s metadata retrieval functions.
  3. Monitor application logs and crash reports for signs of memory corruption or unexpected process termination.
  4. Apply any additional vendor guidance and alerts related to this vulnerability.

Frequently asked questions

Is CVE-2026-19001 being actively exploited?

There are no public reports of exploitation of CVE-2026-19001 as of 2026-09-29.

Which MongoDB BI Connector ODBC Driver versions are affected by CVE-2026-19001?

Versions 1.0.0 through 1.4.8 of the MongoDB BI Connector ODBC Driver are affected; the flaw is fixed in 1.4.9.

Is there a patch for CVE-2026-19001?

Yes. MongoDB released a fix in BI Connector ODBC Driver version 1.4.9.

Does CVE-2026-19001 require authentication?

No. The vulnerability can be triggered by supplying overly long catalog, schema, or object names to the metadata retrieval function without additional privileges.

References