CVE-2026-19002

HIGHCVSS 8.1/10EPSS 0.31%

Last modified

CVE-2026-19002 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
MongodbBi Connector Odbc Driver>= 1.0.0, < 1.4.9

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-19002?
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.
How severe is CVE-2026-19002?
CVE-2026-19002 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2026-19002?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-19002?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST