๐Ÿ” CVE Alert

CVE-2026-19003

HIGH 7.8

MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or folder selection. Depending on build configuration, the result may range from abnormal process termination to, under certain conditions, execution of unintended code in the context of the user running the dialog.

CWE CWE-121
Vendor mongodb
Product bi connector odbc driver
Ecosystems
Industries
Technology
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb bi connector odbc driver

Be the first to know when new high vulnerabilities affecting mongodb bi connector odbc driver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

MongoDB / BI Connector ODBC Driver
1.0.0 < 1.4.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9