Multiple security vulnerabilities affecting MongoDB Server versions The BI Connector ODBC Driver flaws affect every release before version 1 have been identified in MongoDB Server, the BI Connector ODBC Driver, Atlas SQL ODBC Driver, and Schema Builder CLI. The most severe.
CVE-2026-19001 (CVSS 9.8 — Critical): The most severe vulnerability can lead to arbitrary code execution due to a buffer overflow when handling oversized catalog object names in the BI Connector ODBC Driver.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting MongoDB Server versions The BI Connector ODBC Driver flaws affect every release before version 1 have been identified in MongoDB Server, the BI Connector ODBC Driver, Atlas SQL ODBC Driver, and Schema Builder CLI. The most severe.
CVE-2026-19001 (CVSS 9.8 — Critical): The most severe vulnerability can lead to arbitrary code execution due to a buffer overflow when handling oversized catalog object names in the BI Connector ODBC Driver.[emaillocker id="1283"]
CVE-2026-18691 (CVSS 8.8 — High): Improper Authentication in Intra-Cluster Connections Allows Credential Exposure in MongoDB Server versions 7.0, 8.0, and 8.3.
CVE-2026-18692 (CVSS 8.8 — High): Use-After-Free in Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution in MongoDB Server version 8.3.8.
CVE-2026-19004 (CVSS 8.1 — Medium): A Memory-Safety Issue When Handling Stored Procedure Output Parameters exists in the BI Connector ODBC Driver every release before version 1.4.9.
CVE-2026-19002 (CVSS 8.1 — Medium): Crafted database metadata may cause memory corruption in the BI Connector ODBC Driver every release before version 1.4.9.
CVE-2026-19003 (CVSS 7.8 — Low): The BI Connector ODBC Driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings.
CVE-2026-18697 (CVSS 7.5 — Medium): Improper Input Validation in Aggregation Framework Allows Unauthenticated Denial of Service on mongos in MongoDB Server versions 8.3.8, 8.0.29, and 7.0.40.
CVE-2026-18710 (CVSS 6.5 — Low): Cleartext Storage of Sensitive Information in Logging During Client Initialization exists in the Atlas SQL ODBC Driver version 5.9.2.
CVE-2026-18888: Involve similar buffer-overflow patterns. At least six of the 32 flaws mention potential code execution as a possible outcome under certain conditions.
We recommend you to update MongoDB Server to version 1.4.9 or 7.0.40, 8.0.29, or 8.3.8 depending on your installed branch.
The following reports contain further technical details:
[/emaillocker]