Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local, unauthenticated attacker who has logged onto the infrastructure where the MySQL Connector/ODBC executes can cause the component to hang or crash repeatedly. The vulnerability does not provide the attacker with new privileges or direct control of the MySQL service, but the resulting denial of service can disrupt database connectivity for applications that rely on the connector. The CVE describes the attack as requiring human interaction from a person other than the attacker; however, because the attacker only needs local logon access, the barrier to successful exploitation is low.

Affected Systems

The affected product is Oracle MySQL Connector/ODBC version 26.7.0. No other vendors or versions are listed as impacted.

Risk and Exploitability

The vulnerability scores a CVSS 3.1 base of 5.5, with local access, low authentication, and user interaction required. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. Because the impact is a high availability loss and the exploitable conditions are low, the risk remains high for systems running the vulnerable connector. Successful exploitation requires a user with local credentials and a human who can trigger the crash, but once those conditions are met, the attacker can repeatedly interrupt connector operation.

Generated by OpenCVE AI on August 24, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle MySQL Connector/ODBC to a non‑vulnerable release (e.g., version 27.0 or later) using the official Oracle patch.
  • If an immediate upgrade is infeasible, disable or uninstall the 26.7.0 connector from production and other critical systems to prevent accidental crashes.
  • Implement application monitoring that alerts on process hangs or crash events for the connector, and perform periodic manual checks to ensure the service remains responsive.

Generated by OpenCVE AI on August 24, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Denial-of-Service via Local Crash of MySQL Connector/ODBC 26.7.0

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connector/odbc
Oracle Corporation
Oracle Corporation mysql Connectors
Vendors & Products Oracle mysql Connector/odbc
Oracle Corporation
Oracle Corporation mysql Connectors

Thu, 20 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Denial-of-Service via Local Crash of MySQL Connector/ODBC 26.7.0

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Unauthenticated Crashes in MySQL Connector/ODBC 26.7.0
Weaknesses CWE-770

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Unauthenticated Crashes in MySQL Connector/ODBC 26.7.0
Weaknesses CWE-770

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Connector\/odbc
CPEs cpe:2.3:a:oracle:mysql_connector\/odbc:26.7.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/odbc
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Connector/odbc Mysql Connector\/odbc
Oracle Corporation Mysql Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T18:34:58.457Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71073

cve-icon Vulnrichment

Updated: 2026-08-24T18:34:44.227Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:07.387

Modified: 2026-09-02T18:55:56.473

Link: CVE-2026-71073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:30:16Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release