CVE-2026-18888
Last modified
CVE-2026-18888 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Bi Connector Odbc Driver | >= 1.0.0, < 1.4.9 |
References
- https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9Vendor Advisory, Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-18888?
How severe is CVE-2026-18888?
How do I fix CVE-2026-18888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1888The Docus – YouTube Video Playlist plugin for WordPress is v…6.4
- CVE-2026-18881The TableOn – WordPress Posts Table Filterable plugin for Wo…7.5
- CVE-2026-18884The WooCommerce Lottery plugin for WordPress is vulnerable t…7.5
- CVE-2026-18885ServiceNow has remediated a code injection vulnerability tha…10
- CVE-2026-18886ServiceNow has remediated an improper access control vulnera…10
- CVE-2026-18887IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated at…6.5
- CVE-2026-1889The Outgrow plugin for WordPress is vulnerable to Stored Cro…6.4
- CVE-2026-18891IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote a…8.2
- CVE-2026-18895A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-21…8.8
- CVE-2026-18896A vulnerability was determined in lavkush-maurya Student-Reg…6.3
- CVE-2026-18897A vulnerability was identified in UTT HiPER 1250GW up to v3.…8.8
- CVE-2026-18898A security flaw has been discovered in UTT HiPER 1200GW up t…8.8
Are you affected by CVE-2026-18888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
