---
id: CVE-2026-75159
title: >-
  An unauthenticated client that can reach a MongoDB Connector for BI deployment
  configured with Kerberos authentication may cause mongosqld to terminate when
  a crafted authentication exchange encounters a specific GSSAPI error-handling
  co…
summary: >-
  An unauthenticated client that can reach a MongoDB Connector for BI deployment
  configured with Kerberos authentication may cause mongosqld to terminate when
  a crafted authentication exchange encounters a specific GSSAPI error-handling
  co…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-415
vendor: mongodb
product: bi_connector
affected:
  - 'bi_connector >= 2.4.0, < 2.14.30'
patched:
  - bi_connector 2.14.30
published: '2026-08-27'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T16:33:03.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75159'
references:
  - url: >-
      https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00281
epssPercentile: 0.18298
ingestedAt: '2026-09-23T17:28:14.803Z'
---

## Overview

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.

## Affected

- `bi_connector >= 2.4.0, < 2.14.30`

## Remediation

Upgrade past the affected range:

- `bi_connector 2.14.30`
