CVE•Published 2026-08-12•Modified 2026-09-11•1 article on news•5 live references•NVD data
CVE-2026-19001Mongodb · Bi_connector_odbc_driver
Vulnerability data via NVD (ingested)
CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
33
Exploit Prediction Scoring System · top 67% of all CVEs
Weaknesses (CWE)
Description
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.
Timeline
Published 2026-08-12
Modified 2026-09-11
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-19001Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Mongodb Bi Connector Odbc Driver"All exposed Mongodb Bi Connector Odbc Driver instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Bi Connector Odbc Driver"HTTP body or banner mentions "Bi Connector Odbc Driver" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-19001Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-19001Censys host search filtered to this CVE id.
grep.app
CVE-2026-19001Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-19001GitHub code search for direct mentions.
Google dork
"CVE-2026-19001" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (4)
CVE-2026-190014 repos
1diot9/VulnHunter-WhitePython
基于 LLM 的白盒漏洞挖掘 Agent。四条挖掘路径(启发式、快速扫描 Sink 回溯、历史漏洞绕过、无约束)+ Docker 靶场 / 局部 harness / 静态验证,支持互联网复现与攻击链串联。 LLM-based white-box vuln mining agent. Four paths (heuristic, fast-scan sink …
xiaohanarch/HoneyBadgePython
surgifai/mcprtGo
Connection-refcounted MCP server lifecycle manager. Spawn on demand, stop on idle. STDIO refused.
jumbleknot/MovieCollectionManagerTypeScript
Manage your movie collection from a web browser or mobile app