Sceawere
Vulnerability Detail
CVE-2026-71084UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MySQL Connector/ODBC Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- MySQL Connectors
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-08-18T21:18:08.637Z",
"pubdate": "2026-08-18T21:18:08.637Z",
"executiveSummary": "A security vulnerability has been identified within the MySQL Connectors product of Oracle MySQL, specifically impacting the Connector/ODBC component version 26.7.0. This flaw allows an unauthenticated attacker with local logon access to the underlying infrastructure where the MySQL Connector executes to compromise the application. Successful exploitation of this vulnerability yields a CVSS 3.1 base score of 6.8, primarily impacting system availability and data confidentiality. The attack vector is strictly local, requiring no user interaction or privileges, yet granting the capability to execute unauthorized read operations against a subset of accessible data alongside inducing a complete denial of service through application hangs or repeatable crashes. Given the ease of exploitability and the severity of the availability disruption, organizations utilizing the affected version face significant operational risk if unmitigated. The combination of unauthorized data disclosure and persistent service interruption necessitates immediate defensive prioritization for systems hosting the vulnerable ODBC driver.",
"technicalDetails": "The vulnerability resides in the Connector/ODBC component of Oracle MySQL Connectors version 26.7.0. The root cause stems from improper input validation or insecure resource handling during database connectivity operations executed via the ODBC interface. Because the vulnerability is exposed locally (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H), an attacker who has already established a logon session on the host infrastructure can interact directly with the execution space of the MySQL Connectors product without requiring prior authentication or elevated privileges.\nThe attack flow begins with the unauthenticated actor leveraging their local execution environment access to target the running instance or initialization routines of MySQL Connector/ODBC. By supplying crafted inputs, malformed connection parameters, or triggering specific sequence interactions within the local driver context, the attacker induces an unhandled exception or memory management fault. This payload behavior directly precipitates an application hang or a frequently repeatable crash, culminating in a complete denial of service (DoS) condition for processes relying on the connector.\nConcurrently, the architectural flaw allows the attacker to bypass access controls to a limited degree, granting unauthorized read access to a subset of data accessible within the operational memory or file handles of the MySQL Connectors process. The post-exploitation impact is characterized by persistent service unavailability, disrupting database-backed operations on the host, and potential information disclosure of sensitive data processed by the driver subset. The lack of privilege requirements and low attack complexity make this a critical local vector for threat actors who have gained initial foothold access to the host operating system."
}