GSSAPI Error Handling Vulnerability in MongoDB BI Connector Deployments
CVE-2026-75159

8.2HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
27 August 2026

What is CVE-2026-75159?

A specific error-handling condition in the GSSAPI authentication process of the MongoDB Connector for BI can lead to termination of the mongosqld process when an unauthenticated client attempts a crafted authentication exchange. This situation can severely impact the availability of the BI Connector until it is manually restarted, compromising data access and business intelligence functionalities.

Affected Version(s)

BI Connector 2.4.0 < 2.14.30

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.