DIRAS TAKE
Urgent: this is exploitable without authentication or user interaction (CVSS vector shows AV:N/PR:N/UI:N); prioritize updating to 1.4.9 or apply mitigations immediately for exposed services.
What is CVE-2026-19001?
Remote attackers can cause memory corruption in the MongoDB BI Connector ODBC Driver and potentially execute code by supplying unusually long catalog, schema, or object names to a metadata retrieval function. CVE-2026-19001 affects versions 1.0.0 through 1.4.8; the issue is fixed in 1.4.9. Exploitation only requires the ability to invoke the affected metadata functions with overly long identifiers — no additional privileges or user interaction are required in the triggering call.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of MongoDB BI Connector ODBC Driver are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0.0 – before 1.4.9 | 1.4.9 |
Is CVE-2026-19001 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-19001
- Upgrade MongoDB BI Connector ODBC Driver to 1.4.9.
- If immediate upgrade is not possible, restrict access to services that can invoke the driver’s metadata retrieval functions.
- Monitor application logs and crash reports for signs of memory corruption or unexpected process termination.
- Apply any additional vendor guidance and alerts related to this vulnerability.
Frequently asked questions
Is CVE-2026-19001 being actively exploited?
There are no public reports of exploitation of CVE-2026-19001 as of 2026-09-29.
Which MongoDB BI Connector ODBC Driver versions are affected by CVE-2026-19001?
Versions 1.0.0 through 1.4.8 of the MongoDB BI Connector ODBC Driver are affected; the flaw is fixed in 1.4.9.
Is there a patch for CVE-2026-19001?
Yes. MongoDB released a fix in BI Connector ODBC Driver version 1.4.9.
Does CVE-2026-19001 require authentication?
No. The vulnerability can be triggered by supplying overly long catalog, schema, or object names to the metadata retrieval function without additional privileges.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19001
- cve.org/CVERecord?id=CVE-2026-19001
- github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9
- All MongoDB CVEs on CVE Radar
- CVEs published in September 2026