Threat Advisory

Attackers Can Execute Arbitrary Code with MongoDB BI Connector ODBC Driver Flaw

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting MongoDB Server versions The BI Connector ODBC Driver flaws affect every release before version 1 have been identified in MongoDB Server, the BI Connector ODBC Driver, Atlas SQL ODBC Driver, and Schema Builder CLI. The most severe.

CVE-2026-19001 (CVSS 9.8 — Critical): The most severe vulnerability can lead to arbitrary code execution due to a buffer overflow when handling oversized catalog object names in the BI Connector ODBC Driver.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting MongoDB Server versions The BI Connector ODBC Driver flaws affect every release before version 1 have been identified in MongoDB Server, the BI Connector ODBC Driver, Atlas SQL ODBC Driver, and Schema Builder CLI. The most severe.

CVE-2026-19001 (CVSS 9.8 — Critical): The most severe vulnerability can lead to arbitrary code execution due to a buffer overflow when handling oversized catalog object names in the BI Connector ODBC Driver.[emaillocker id="1283"]

CVE-2026-18691 (CVSS 8.8 — High): Improper Authentication in Intra-Cluster Connections Allows Credential Exposure in MongoDB Server versions 7.0, 8.0, and 8.3.

CVE-2026-18692 (CVSS 8.8 — High): Use-After-Free in Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution in MongoDB Server version 8.3.8.

CVE-2026-19004 (CVSS 8.1 — Medium): A Memory-Safety Issue When Handling Stored Procedure Output Parameters exists in the BI Connector ODBC Driver every release before version 1.4.9.

CVE-2026-19002 (CVSS 8.1 — Medium): Crafted database metadata may cause memory corruption in the BI Connector ODBC Driver every release before version 1.4.9.

CVE-2026-19003 (CVSS 7.8 — Low): The BI Connector ODBC Driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings.

CVE-2026-18697 (CVSS 7.5 — Medium): Improper Input Validation in Aggregation Framework Allows Unauthenticated Denial of Service on mongos in MongoDB Server versions 8.3.8, 8.0.29, and 7.0.40.

CVE-2026-18710 (CVSS 6.5 — Low): Cleartext Storage of Sensitive Information in Logging During Client Initialization exists in the Atlas SQL ODBC Driver version 5.9.2.

CVE-2026-18888: Involve similar buffer-overflow patterns. At least six of the 32 flaws mention potential code execution as a possible outcome under certain conditions.

RECOMMENDATION:

We recommend you to update MongoDB Server to version 1.4.9 or 7.0.40, 8.0.29, or 8.3.8 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu