High severity8.1NVD Advisory· Published Aug 12, 2026· Updated Sep 11, 2026
CVE-2026-19002
CVE-2026-19002
Description
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9nvdVendor AdvisoryRelease Notes
News mentions
1- MongoDB: 25 Vulnerabilities Disclosed, Including Critical BI Connector FlawsVypr Intelligence · Aug 12, 2026