Impact
A local, unauthenticated attacker who has logged onto the infrastructure where the MySQL Connector/ODBC executes can cause the component to hang or crash repeatedly. The vulnerability does not provide the attacker with new privileges or direct control of the MySQL service, but the resulting denial of service can disrupt database connectivity for applications that rely on the connector. The CVE describes the attack as requiring human interaction from a person other than the attacker; however, because the attacker only needs local logon access, the barrier to successful exploitation is low.
Affected Systems
The affected product is Oracle MySQL Connector/ODBC version 26.7.0. No other vendors or versions are listed as impacted.
Risk and Exploitability
The vulnerability scores a CVSS 3.1 base of 5.5, with local access, low authentication, and user interaction required. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. Because the impact is a high availability loss and the exploitable conditions are low, the risk remains high for systems running the vulnerable connector. Successful exploitation requires a user with local credentials and a human who can trigger the crash, but once those conditions are met, the attacker can repeatedly interrupt connector operation.
OpenCVE Enrichment