Impact
The vulnerability arises from improper memory handling during Kerberos authentication failures in the MongoDB Connector for BI. A crafted authentication exchange that triggers a specific GSSAPI error condition can cause the mongosqld process to crash, resulting in an abrupt termination of the Connector service. The flaw is a use‑after‑free condition identified as CWE‑415, which can lead to denial of service by interrupting connectivity for BI clients.
Affected Systems
Affected vendors and products are MongoDB's BI Connector service. The vulnerability impacts deployments that use Kerberos authentication. No specific version information is listed, so any installation using Kerberos that matches the description should be considered at risk until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 8.2 denotes a high severity threat, and the absence of an EPSS rating means the exploitation probability is unknown, while the vulnerability is not listed in CISA's KEV catalog. Attackers can reach the vulnerable component over the network from an unauthenticated client, leveraging the Kerberos error path to crash the process. Given the high CVSS, the risk is significant, especially in environments where uninterrupted BI availability is critical.
OpenCVE Enrichment