Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81532— BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corruption

Quick assessment

Affected
MongoDB BI Connector ODBC Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

能够提交 SQL 的应用程序用户,如果使用 MongoDB Connector for BI ODBC 驱动程序,可以提供一个位置游标语句,其游标名称超过了内部固定长度缓冲区的大小。由于在驱动程序构建其诊断消息之前,名称的长度未受限制,与该缓冲区相邻的内存会被用户提供的内容覆盖。这可能导致宿主应用程序进程终止,并可能允许在其中执行非预期的代码。

CVSS 8.8 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81532

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corruption
Source: CVE Program / CVE List V5
Vulnerability Description
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that buffer is overwritten with user-supplied content. This can terminate the hosting application process and may allow unintended code to run within it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB BI Connector ODBC Driver 0 ~ 1.4.10 -

II. Public POCs for CVE-2026-81532

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81532

登录查看更多情报信息。

Vendor Pages for CVE-2026-81532 (1)

Same Patch Batch · MongoDB · 2026-08-28 · 11 CVEs total

CVE-2026-77586 8.0 HIGH MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output
CVE-2026-81490 7.7 HIGH MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of
CVE-2026-81517 7.5 HIGH MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S
CVE-2026-81518 7.5 HIGH BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections
CVE-2026-81520 7.5 HIGH MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus
CVE-2026-81533 7.1 HIGH MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values
CVE-2026-76798 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports
CVE-2026-76797 6.3 MEDIUM MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate
CVE-2026-77184 5.2 MEDIUM MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O
CVE-2026-76794 4.6 MEDIUM MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da

IV. Related Vulnerabilities

V. Comments for CVE-2026-81532

No comments yet


Leave a comment