Impact
A local attacker who can log on to the infrastructure where Oracle MySQL Connector/ODBC executes can trigger a denial-of-service condition by causing the driver to hang or crash. Additionally, the vulnerability allows the attacker to read a subset of data that the connector has access to, thereby exposing confidential information. The weakness is an improper access control flaw identified as CWE-284, and it also includes a heap-based buffer overread identified as CWE-125.
Affected Systems
The vulnerability affects Oracle Corporation’s MySQL Connectors product, specifically Connector/ODBC version 26.7.0.
Risk and Exploitability
The CVSS v3.1 base score is 6.8 with local access required and no user interaction. The EPSS score is less than 1%, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires only local system access, so a compromised workstation or a service account with sufficient privileges could leverage the flaw. No network‑based attack vector is listed, so risk is confined to systems that host the connector and allow local execution.
OpenCVE Enrichment