Medium severity6.5NVD Advisory· Published Aug 12, 2026· Updated Sep 11, 2026
CVE-2026-18888
CVE-2026-18888
Description
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9nvdVendor AdvisoryRelease Notes
News mentions
1- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026