PT-2026-83364 · Mongodb · Mongodb Bi Connector Odbc Driver
CVE-2026-81533
·
Published
2026-08-28
·
Updated
2026-09-12
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
MongoDB BI Connector ODBC Driver (affected versions not specified)
Description
A memory-safety issue exists when the driver processes a SQL statement containing an unusually long sequence of digits following a LIMIT clause. This occurs when the optional prefetch setting is enabled, as the driver copies the digit sequence into a fixed-size internal buffer without verifying its length. An attacker capable of influencing the numeric portion of the LIMIT clause could cause the application process to terminate unexpectedly or corrupt adjacent memory.
Recommendations
Disable the prefetch setting to mitigate the risk.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Bi Connector Odbc Driver