【Security Vulnerability Alert】MongoDB BI Connector ODBC Driver Contains a High-Risk Security Vulnerability(CVE-2026-19001), Please Confirm and Patch as Soon as Possible

 
2026/9/9 ~ 2027/3/9
View Count:44

Forwarded from National Information Sharing and Analysis Center Cybersecurity Information Alert NISAC-200-202609-00000002

[Content Description]
Researchers discovered that MongoDB BI Connector ODBC Driver contains an Integer Overflow vulnerability(CVE-2026-19001). Unauthenticated remote attackers can cause a buffer overflow by passing an excessively long name parameter, resulting in memory corruption and abnormal program termination, and may execute arbitrary code. Please confirm and patch as soon as possible.

[Affected Platforms]
MongoDB BI Connector ODBC Driver versions 1.0.0 to 1.4.9(exclusive)

[Recommended Measures]
The official source has released a patch for the vulnerability. Please upgrade MongoDB BI Connector ODBC Driver to version 1.4.9(inclusive) or later. For detailed information, please refer to the official advisory at the following URL: https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19001
2. https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9

Files
system_update_alt參考資料1
system_update_alt參考資料2
Top↑