SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75159

MEDIUM · CVSS 5.9 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MongoDB Connector for BI deployments using Kerberos authentication are vulnerable to a denial-of-service condition triggered by an unauthenticated client, which can cause the mongosqld process to terminate due to a specific GSSAPI error. This interruption affects the availability of the BI Connector until the service is manually restarted. Organizations using affected versions of Exchange and MongoDB should prioritize addressing this vulnerability to maintain service continuity.

CVE
CVE-2026-75159
Severity
MEDIUM
CVSS
5.9
EPSS
0.26%
Exchange MongoDB

Original NVD Description

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.