Integer overflow in BI Connector ODBC Driver - CVE-2026-19001

 

Integer overflow in BI Connector ODBC Driver - CVE-2026-19001

Published: August 18, 2026


Vulnerability identifier: #VU144150
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19001
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in metadata retrieval functions when handling unusually long catalog, schema, or object names. A remote attacker can supply an oversized catalog, schema, or object name to trigger memory corruption and execute arbitrary code.

Successful exploitation may also cause abnormal termination within the calling application's process.


Affected software

BI Connector ODBC Driver

How to mitigate CVE-2026-19001

Install security update from vendor's website.

BI Connector ODBC Driver - update to 1.4.9

External References

Related Security Bulletins