Sceawere

Vulnerability Detail

CVE-2026-71079UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MySQL Connectors Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
MySQL Connectors
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:18:08.063Z",
  "pubdate": "2026-08-18T21:18:08.063Z",
  "executiveSummary": "A vulnerability exists within the MySQL Connectors product of Oracle MySQL, specifically targeting the Connector/ODBC component version 26.7.0. This security flaw enables a low-privileged threat actor with network access to compromise the stability of the affected software. The primary vulnerability type is a Denial of Service (DoS) condition, which manifests as an unauthorized ability to cause a system hang or a frequently repeatable crash of the MySQL Connectors instance. From a risk perspective, successful exploitation severely impacts service availability without compromising confidentiality or integrity data vectors. The attack requires minimal attacker capabilities, specifically low privileges and network access across multiple protocols, but does not necessitate user interaction. Because the vulnerability is easily exploitable over the network, organizations utilizing the specified version face operational risks regarding service uptime and application resilience. The CVSS 3.1 Base Score is 6.5, reflecting the high availability impact under network vector conditions.",
  "technicalDetails": "The vulnerability resides in the Connector/ODBC component of Oracle MySQL Connectors version 26.7.0. The underlying root cause involves improper handling of network-based communications and protocol inputs processed by the component, leading to execution paths that result in resource exhaustion, unhandled exceptions, or fatal application errors. Exploitation of this flaw occurs remotely over the network, utilizing multiple protocols supported by the Connector/ODBC interface. An attacker requires network access and low privileges to interact with the vulnerable service endpoint. The attack flow initiates when the authenticated, low-privileged attacker transmits malformed or specifically crafted protocol payloads to the MySQL Connectors instance. Upon receipt and subsequent processing of these payloads by the vulnerable component, the software encounters an exceptional state or logic error that it cannot recover from. This behavior triggers either a complete application hang, halting further request processing, or a repeatable crash that terminates the process entirely. The post-exploitation impact is strictly confined to availability, manifesting as a complete Denial of Service (DoS) for the affected MySQL Connectors deployment. The vulnerability exhibits a CVSS 3.1 vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating Network attack vector (AV:N), Low attack complexity (AC:L), Low privileges required (PR:L), No user interaction required (UI:N), Unchanged scope (S:U), and High availability impact (A:H) with no impact on confidentiality or integrity."
}
CVE-2026-71079: MySQL Connectors Denial of Service (MEDIUM Severity, CVSS: 6.5) - Sceawere