← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 20:29via CVEFeed

CVE-2026-18888 - MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data

Brief

CVE ID : CVE-2026-18888

Published : Aug. 12, 2026, 8:29 p. m.

  • 35 minutes ago

Description : The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory.

A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.

Severity: 7.1

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed