Executive brief
MongoDB Connector for BI is a tool that allows business intelligence applications to query MongoDB databases. When configured with Kerberos authentication, an unauthenticated attacker on the network can craft malicious authentication requests that cause the mongosqld process to crash, making the connector unavailable until it is manually restarted. This disrupts BI reporting and analytics functionality for affected organizations.
Technical details
The vulnerability exists in the GSSAPI authentication error handling within mongosqld when Kerberos authentication is enabled. An unauthenticated network client can send specially crafted authentication exchanges that trigger a specific error condition in the GSSAPI library interaction, causing mongosqld to terminate abnormally. The attack requires network reachability to the BI Connector deployment but no valid credentials. The impact is availability disruption (denial of service) requiring process restart to restore functionality. A fix is expected to be available in MongoDB's release notes.
Affected products
- MongoDB Connector for BI <UNKNOWN>
Timeline
- 2026-08-27: published