CVE-2026-75159: MongoDB BI Connector

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.

Affected products

  • MongoDB BI Connector: from 2.4.0, before 2.14.30 (fixed in 2.14.30)

Published 2026-08-27. Last modified 2026-09-23.