MongoDB disclosed five vulnerabilities in the BI Connector ODBC Driver, including one critical flaw and four high-severity issues affecting releases earlier than 1.4.9. Reported impacts include remote code execution, information disclosure, and denial of service, prompting guidance from Italy’s ACN/CSIRT to apply the vendor’s security updates.
One of the high-severity bugs, CVE-2026-19003, is a memory corruption issue in the driver’s setup dialog that can write outside an allocated buffer when a data source with an oversized path is opened and the user triggers file or folder selection. MongoDB said the flaw is not remotely exploitable, but it can still crash the process and, under some build configurations and conditions, lead to unintended code execution in the context of the logged-in user.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
MongoDB disclosed CVE-2026-19003, a high-severity memory corruption flaw in the BI Connector ODBC Driver caused by incorrect buffer capacity calculation when the setup dialog opens a malformed data source with an oversized path. MongoDB said the issue is not remotely exploitable but can cause crashes and, in some conditions, unintended code execution in the user's context.
MongoDB published mongo-bi-connector-odbc-driver version 1.4.9, stating that it fixes five security issues: CVE-2026-18888, CVE-2026-19001, CVE-2026-19002, CVE-2026-19003, and CVE-2026-19004. The release notes describe added bounds-checking or clamping logic for large floats, catalog function name lengths, client app integration parameter sizes, DSN path field sizes, and buffers.
Italy's ACN reported five vulnerabilities affecting the MongoDB BI Connector ODBC Driver, including one critical and four high-severity issues. The notice said versions earlier than 1.4.9 are affected and recommended updating according to MongoDB's security bulletins.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.