An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb bi Connector Odbc Driver |
|
| Vendors & Products |
Mongodb
Mongodb bi Connector Odbc Driver |
Wed, 12 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution. | |
| Title | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2026-08-12T20:33:13.882Z
Updated: 2026-08-13T14:09:20.563Z
Reserved: 2026-08-05T19:46:33.537Z
Link: CVE-2026-19004
Updated: 2026-08-13T14:09:17.311Z
Status : Received
Published: 2026-08-12T21:17:37.577
Modified: 2026-08-13T15:19:37.067
Link: CVE-2026-19004
No data.