Forwarded from National Information Sharing and Analysis Center Cybersecurity Information Alert NISAC-200-202609-00000002
[Content Description]
Researchers discovered that MongoDB BI Connector ODBC Driver contains an Integer Overflow vulnerability(CVE-2026-19001). Unauthenticated remote attackers can cause a buffer overflow by passing an excessively long name parameter, resulting in memory corruption and abnormal program termination, and may execute arbitrary code. Please confirm and patch as soon as possible.
[Affected Platforms]
MongoDB BI Connector ODBC Driver versions 1.0.0 to 1.4.9(exclusive)
[Recommended Measures]
The official source has released a patch for the vulnerability. Please upgrade MongoDB BI Connector ODBC Driver to version 1.4.9(inclusive) or later. For detailed information, please refer to the official advisory at the following URL: https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19001
2. https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9