【Vulnerability Alert】MongoDB BI Connector ODBC Driver Contains a High-Risk Security Vulnerability (CVE-2026-19001). Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-09-04 update date : 2026-09-04

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026082804084040 Publication Time 2026-08-28 16:03:40
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-28 16:03:40
Impact Level Medium  
[Subject]
【Vulnerability Alert】MongoDB BI Connector ODBC Driver Contains a High-Risk Security Vulnerability (CVE-2026-19001). Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000002

Researchers discovered that MongoDB BI Connector ODBC Driver contains an Integer Overflow vulnerability (CVE-2026-19001). An unauthenticated remote attacker may pass an excessively long name parameter to cause a buffer overflow, resulting in memory corruption and abnormal program termination, and may potentially execute arbitrary code. Please confirm and apply patches as soon as possible.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

MongoDB BI Connector ODBC Driver versions 1.0.0 to versions prior to 1.4.9

[Recommended Actions]

The official vendor has released a patch for the vulnerability. Please upgrade MongoDB BI Connector ODBC Driver to version 1.4.9 or later. For detailed information, please refer to the official advisory. The URL is as follows: https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-19001
2. https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center