PatchSiren cyber security CVE debrief
CVE-2026-19004 MongoDB CVE debrief
The MongoDB BI Connector ODBC Driver is vulnerable to a memory-safety issue when processing output parameters from a stored procedure. This issue requires connecting to an untrusted or impersonated database server that returns crafted metadata, which may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution. Organizations should verify their inventory and check for vendor remediation. The CVE record was published on 2026-08-12T21:17:37.577Z and has not been modified since then. Affected product deployments should be identified and owners assigned for follow-up.
- Vendor
- MongoDB
- Product
- BI Connector ODBC Driver
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-28
Who should care
Organizations using the MongoDB BI Connector ODBC Driver, particularly those connecting to untrusted or impersonated database servers, should prioritize verifying their inventory and checking for vendor remediation. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Affected operators, platforms, and security teams should review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retesting of remediated assets, and documentation of evidence should be tracked and verified before closing the item. The CVE record was published on 2026-08-12T21:17:37.577Z and has not been modified since then. The vulnerability affects MongoDB BI Connector ODBC Driver users who connect to untrusted or impersonated database servers, requiring them to verify their inventory and check for vendor remediation or updates. Users should also implement compensating controls, such as validating database server connections, and review relevant monitoring, detection, and logs for exposed assets that need extra review. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented is crucial. The vulnerability has a significant impact on affected product deployments, and organizations should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Reviewing compensating controls for exposed systems while remediation is scheduled and verified is essential. Checking relevant monitoring, detection, and logs for exposed assets that need extra review helps ensure the vulnerability is properly managed. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented ensures that the vulnerability is fully addressed. Organizations should also consider the operational impact of the vulnerability and the source-confidence limits of the information provided. A thorough review of the CVE record and official advisory is necessary to understand the affected scope, severity, и
Technical summary
The MongoDB BI Connector ODBC Driver is vulnerable to a memory-safety issue when processing output parameters from a stored procedure. This issue requires connecting to an untrusted or impersonated database server that returns crafted metadata, which may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The CVE record indicates that the issue can be triggered by connecting to an untrusted or impersonated database server.
Defensive priority
Organizations using the MongoDB BI Connector ODBC Driver should prioritize verifying their inventory and checking for vendor remediation.
Recommended defensive actions
- Verify inventory of systems using the MongoDB BI Connector ODBC Driver
- Check for vendor remediation or updates
- Implement compensating controls, such as validating database server connections
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record indicates a memory-safety issue in the MongoDB BI Connector ODBC Driver when processing output parameters from a stored procedure. The issue requires connecting to an untrusted or impersonated database server that returns crafted metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19004 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19004
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19004 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19004
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.