{"id":"CVE-2026-75159","title":"An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling co…","summary":"An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling co…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-415"],"vendor":"mongodb","product":"bi_connector","affected":["bi_connector >= 2.4.0, < 2.14.30"],"patched":["bi_connector 2.14.30"],"published":"2026-08-27","updated":"2026-09-23","sourceUpdated":"2026-09-23T16:33:03.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75159","references":[{"url":"https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.00264,"epssPercentile":0.18566,"ingestedAt":"2026-09-23T17:28:14.803Z","slug":"CVE-2026-75159","body":"## Overview\n\nAn unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.\n\n## Affected\n\n- `bi_connector >= 2.4.0, < 2.14.30`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bi_connector 2.14.30`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}