SB2026081849 - Integer overflow in BI Connector ODBC Driver



SB2026081849 - Integer overflow in BI Connector ODBC Driver

Published: August 18, 2026

Security Bulletin ID SB2026081849
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Integer overflow (CVE-ID: CVE-2026-19001)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in metadata retrieval functions when handling unusually long catalog, schema, or object names. A remote attacker can supply an oversized catalog, schema, or object name to trigger memory corruption and execute arbitrary code.

Successful exploitation may also cause abnormal termination within the calling application's process.


Remediation

Install update from vendor's website.