๐Ÿ” CVE Alert

CVE-2026-75159

MEDIUM 5.9

MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process Termination

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.

CWE CWE-415
Vendor mongodb
Product bi connector
Ecosystems
Industries
Technology
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb bi connector

Be the first to know when new medium vulnerabilities affecting mongodb bi connector are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

MongoDB / BI Connector
2.4.0 < 2.14.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mongodb.com: https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30