AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19001

CRITICAL · CVSS 9.8 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The MongoDB BI Connector ODBC Driver is vulnerable due to a buffer overflow issue that occurs when excessively long catalog, schema, or object names are provided to a metadata retrieval function. This vulnerability can lead to memory corruption, potentially causing application crashes and, in some cases, allowing for arbitrary code execution. Organizations using this driver should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19001
Severity
CRITICAL
CVSS
9.8
EPSS
0.38%
MongoDB

Original NVD Description

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.