能够提交 SQL 的应用程序用户,如果使用 MongoDB Connector for BI ODBC 驱动程序,可以提供一个位置游标语句,其游标名称超过了内部固定长度缓冲区的大小。由于在驱动程序构建其诊断消息之前,名称的长度未受限制,与该缓冲区相邻的内存会被用户提供的内容覆盖。这可能导致宿主应用程序进程终止,并可能允许在其中执行非预期的代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | BI Connector ODBC Driver | 0 ~ 1.4.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77586 | 8.0 HIGH | MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output |
| CVE-2026-81490 | 7.7 HIGH | MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of |
| CVE-2026-81517 | 7.5 HIGH | MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S |
| CVE-2026-81518 | 7.5 HIGH | BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections |
| CVE-2026-81520 | 7.5 HIGH | MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus |
| CVE-2026-81533 | 7.1 HIGH | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values |
| CVE-2026-76798 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports |
| CVE-2026-76797 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate |
| CVE-2026-77184 | 5.2 MEDIUM | MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O |
| CVE-2026-76794 | 4.6 MEDIUM | MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da |
No comments yet