Loading market data...
← Back to CVE feed

CVE-2026-19002

HIGH CVSS 8.1 View on NVD ↗

Description

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Aug 12, 2026 21:17 UTC Modified: Aug 13, 2026 13:17 UTC