CVE-2026-75159: MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process Termination

Published Aug 27, 2026
·
Updated

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.

Affected Software

1 affected component
MongoDB Connector for BI

Event History

Aug 27, 2026
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments of MongoDB Connector for BI that use Kerberos authentication are exposed if an unauthenticated client can reach the mongosqld service. The issue affects availability rather than confidentiality or integrity.

2

What does an attacker need to exploit it?

An attacker needs network reachability to the BI Connector and must send a crafted authentication exchange that triggers a specific GSSAPI error-handling condition. No prior authentication or user interaction is required.

3

What is the operational impact if exploitation succeeds?

Successful exploitation can cause the mongosqld process to terminate, interrupting BI Connector availability until the process restarts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203