CVE-2026-81533
MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying the digit sequence into a fixed-size internal buffer without checking its length. A user able to influence the numeric portion of a LIMIT clause could cause the hosting application process to terminate unexpectedly or corrupt adjacent memory in that process.
| CWE | CWE-121 |
| Vendor | mongodb |
| Product | bi connector odbc driver |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for mongodb bi connector odbc driver
Be the first to know when new high vulnerabilities affecting mongodb bi connector odbc driver are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Affected Versions
MongoDB / BI Connector ODBC Driver
0 < 1.4.10