# CVE-2026-75159

## Summary

- **CVE ID:** CVE-2026-75159
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-415
- **Published:** Aug 27, 2026
- **Last Modified:** Aug 27, 2026

## Description

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.

## Affected Products

- MongoDB — BI Connector (2.4.0)

## References

- [CNA](https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 18.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._