Posting Date: 2026/09/04
【Vulnerability Alert】High-Risk Security Vulnerability in MongoDB BI Connector ODBC Driver (CVE-2026-19001), Please Verify and Patch Immediately
- Subject: 【Vulnerability Alert】High-Risk Security Vulnerability in MongoDB BI Connector ODBC Driver (CVE-2026-19001), Please Verify and Patch Immediately
- Description:
- Forwarded Security Alert from National Information Security Sharing and Analysis Center (NISAC) Alert ID: NISAC-200-202609-00000002
- Researchers have discovered an Integer Overflow vulnerability (CVE-2026-19001) in MongoDB BI Connector ODBC Driver. An unauthenticated remote attacker could pass an excessively long name parameter to cause a buffer overflow, resulting in memory corruption, abnormal program termination, and potential arbitrary code execution. Please verify and apply patches as soon as possible.
- Affected Systems:
- MongoDB BI Connector ODBC Driver versions 1.0.0 up to (excluding) 1.4.9
- Recommendations:
- The vendor has released a security patch for this vulnerability. Please upgrade MongoDB BI Connector ODBC Driver to version 1.4.9 or later. For detailed information, please refer to the official release announcement at: https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9
- References:
Computer and Communication Center
Network System Division