Description
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.
Published: 2026-08-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from improper memory handling during Kerberos authentication failures in the MongoDB Connector for BI. A crafted authentication exchange that triggers a specific GSSAPI error condition can cause the mongosqld process to crash, resulting in an abrupt termination of the Connector service. The flaw is a use‑after‑free condition identified as CWE‑415, which can lead to denial of service by interrupting connectivity for BI clients.

Affected Systems

Affected vendors and products are MongoDB's BI Connector service. The vulnerability impacts deployments that use Kerberos authentication. No specific version information is listed, so any installation using Kerberos that matches the description should be considered at risk until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 8.2 denotes a high severity threat, and the absence of an EPSS rating means the exploitation probability is unknown, while the vulnerability is not listed in CISA's KEV catalog. Attackers can reach the vulnerable component over the network from an unauthenticated client, leveraging the Kerberos error path to crash the process. Given the high CVSS, the risk is significant, especially in environments where uninterrupted BI availability is critical.

Generated by OpenCVE AI on August 27, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MongoDB Connector for BI to a version that includes the fix; consult the release notes at the provided link for the specific corrected release.
  • Restrict inbound traffic to the BI Connector so that only trusted internal hosts or networks can reach it.
  • Verify that Kerberos keytabs, principals, and service principals are correctly configured to avoid unintended error conditions during authentication.
  • If an upgrade is not immediately possible, monitor the service for unexpected restarts and apply the vendor fix as soon as it becomes available.

Generated by OpenCVE AI on August 27, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb bi Connector
Vendors & Products Mongodb
Mongodb bi Connector

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.
Title MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process Termination
Weaknesses CWE-415
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Bi Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-08-27T19:29:27.529Z

Reserved: 2026-08-17T19:11:21.383Z

Link: CVE-2026-75159

cve-icon Vulnrichment

Updated: 2026-08-27T19:29:20.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-27T17:19:54.780

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-75159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:14:14Z

Weaknesses