CVE-2026-75159: MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process Termination
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments of MongoDB Connector for BI that use Kerberos authentication are exposed if an unauthenticated client can reach the mongosqld service. The issue affects availability rather than confidentiality or integrity.
What does an attacker need to exploit it?
An attacker needs network reachability to the BI Connector and must send a crafted authentication exchange that triggers a specific GSSAPI error-handling condition. No prior authentication or user interaction is required.
What is the operational impact if exploitation succeeds?
Successful exploitation can cause the mongosqld process to terminate, interrupting BI Connector availability until the process restarts.