Sceawere

Vulnerability Detail

CVE-2026-71073UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MySQL Connector ODBC Denial of Service Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
MySQL Connectors
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors.
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-18T21:18:07.387Z",
  "pubdate": "2026-08-18T21:18:07.387Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the MySQL Connectors product of Oracle MySQL, specifically targeting the Connector/ODBC component version 26.7.0. This vulnerability allows an unauthenticated threat actor with physical or logical logon access to the underlying infrastructure where the MySQL Connectors execute to compromise the availability of the application. Successful exploitation of this flaw requires human interaction from a user other than the attacker, typically involving the execution or interaction with a maliciously crafted database connection string, file, or application routine processed by the ODBC driver.\nThe primary impact of a successful attack is directed entirely at the availability vector, resulting in an unauthorized ability to cause a system hang or a frequently repeatable application crash, culminating in a complete Denial of Service (DoS) condition for the affected MySQL Connectors instance. The vulnerability carries a CVSS 3.1 Base Score of 5.5 with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating local attack vector execution, low attack complexity, no required privileges, required user interaction, unchanged scope, and high impact to availability with zero impact to confidentiality or integrity.",
  "technicalDetails": "The vulnerability resides in the Connector/ODBC component of Oracle MySQL Connectors version 26.7.0. The root cause stems from improper input validation, memory handling, or exception management within the driver when processing specific data structures, connection parameters, or query responses. Because the affected software runs within the context of an infrastructure accessible locally, the attack vector (AV:L) dictates that the adversary must already possess logon access to the host operating system, whether via interactive shell, remote desktop session, or compromised local execution context.\nThe attack flow proceeds in a sequential manner requiring specific preconditions. First, an unauthenticated attacker (PR:N) with local infrastructure access deposits, configures, or prepares a malicious payload—such as a specially crafted DSN (Data Source Name) configuration, a malicious file parsed by the driver, or an application invocation routine. Second, the attacker induces human interaction (UI:R) by tricking another user or administrator sharing or utilizing the infrastructure into executing, opening, or interacting with the vulnerable application instance or connection profile that invokes the Connector/ODBC driver. Third, upon processing the malformed input or encountering the unexpected state during execution, the Connector/ODBC component encounters an unhandled exception, severe memory corruption, or an infinite execution loop.\nThis operational failure directly disrupts the execution thread of the MySQL Connectors process, leading immediately to an application hang or a fatal crash. Because the crash is frequently repeatable, an attacker can induce persistent DoS conditions against dependent applications relying on the ODBC driver. The vulnerability does not grant the attacker elevated privileges (PR:N), nor does it allow for arbitrary code execution, privilege escalation, or unauthorized access to sensitive database contents (C:N, I:N), confining the post-exploitation impact strictly to availability degradation (A:H)."
}
CVE-2026-71073: MySQL Connector ODBC Denial of Service Vulnerability (MEDIUM Severity, CVSS: 5.5) - Sceawere