cve-2026-71084

MEDIUM CVSS 6.8 opencve
Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).

Timeline
Published
2026-08-18 21:18 UTC
Last Modified
2026-09-02
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 6.8 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H mitre
3.1 6.8 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H nvd
3.1 6.8 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H opencve
3.1 6.8 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H redhat
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-71084",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "26.7.0"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "product": "mysql_connector/odbc",
        "vendor": "oracle"
      },
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "26.7.0"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "MySQL Connectors",
          "source": "cna",
          "vendor": "Oracle Corporation"
        },
        "product": "mysql_connectors",
        "vendor": "oracle"
      }
    ],
    "created": "2026-08-19T08:45:03.858644+00:00",
    "updated": "2026-08-28T20:15:06.357216+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$mysql_connector/odbc",
      "oracle$PRODUCT$mysql_connectors"
    ]
  },
  "epss": {
    "score": 0.00169
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:mysql_connector\\/odbc:26.7.0:*:*:*:*:*:*:*"
    ],
    "created": "2026-08-18T21:03:26.154000+00:00",
    "description": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC).   The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/71xxx/CVE-2026-71084.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspuaug2026.html"
    ],
    "title": null,
    "updated": "2026-08-19T16:02:22.938000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$mysql_connector\\/odbc"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:oracle:mysql_connector\\/odbc:26.7.0:*:*:*:*:*:*:*"
    ],
    "created": "2026-08-18T21:18:08.637000+00:00",
    "description": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC).   The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-71084.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspuaug2026.html"
    ],
    "title": null,
    "updated": "2026-09-02T18:55:14.130000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$mysql_connector\\/odbc"
    ],
    "weaknesses": [
      "CWE-284"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-08-18T21:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC).   The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$mysql_connector\\/odbc"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:mysql_connector\\/odbc:26.7.0:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$mysql_connector\\/odbc"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 6.8,
                  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "d243b715-7491-43a4-bacb-d4a4af053a96"
      },
      {
        "created": "2026-08-19T09:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "MySQL Connector/ODBC 26.7.0 Local Denial of Service and Sensitive Data Exposure",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-200",
                "CWE-285"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "f850c908-110f-4392-a244-60ab49f4484a"
      },
      {
        "created": "2026-08-19T14:30:00+00:00",
        "data": [
          {
            "details": [
              "oracle$PRODUCT$mysql_connector/odbc",
              "oracle$PRODUCT$mysql_connectors"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "oracle$PRODUCT$mysql_connector/odbc",
                "oracle$PRODUCT$mysql_connectors"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "f1381a95-45a6-4d30-9d2b-dde266b1b472"
      },
      {
        "created": "2026-08-19T16:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "17f5be5e-1a1b-45ca-b221-4557d2a4747e"
      },
      {
        "created": "2026-08-19T21:15:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "MySQL Connector/ODBC 26.7.0 Local Denial of Service and Sensitive Data Exposure"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-200",
                "CWE-285"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "2ba5a868-9d7b-4ecc-8014-f83e652a62da"
      },
      {
        "created": "2026-08-20T06:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Local Denial of Service and Data Exposure via Oracle MySQL Connector/ODBC 26.7.0",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "d2df3e4f-e1ba-4a95-98fe-8ccd552fdd0d"
      },
      {
        "created": "2026-08-20T18:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Local Denial of Service and Data Exposure via Oracle MySQL Connector/ODBC 26.7.0"
            },
            "type": "title"
          }
        ],
        "id": "c50e672f-879b-4b98-93bf-b7a3c5c15d4e"
      },
      {
        "created": "2026-08-27T18:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via unauthenticated local access",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-125"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://nvd.nist.gov/vuln/detail/CVE-2026-71084",
                "https://www.cve.org/CVERecord?id=CVE-2026-71084"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "threat_severity": {
                  "new": "Moderate",
                  "old": null
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "363bd103-221c-4526-bfb6-ae185db8e1e9"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:mysql_connector\\/odbc:26.7.0:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-08-18T21:03:26+00:00",
      "provider": "redhat"
    },
    "description": {
      "data": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC).   The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 6.8,
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00169
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {},
        "provider": null
      },
      "threat_severity": {
        "data": "Moderate",
        "provider": "redhat"
      }
    },
    "references": {
      "data": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-71084",
        "https://www.cve.org/CVERecord?id=CVE-2026-71084",
        "https://www.oracle.com/security-alerts/cspuaug2026.html"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    },
    "title": {
      "data": "mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via unauthenticated local access",
      "provider": "redhat"
    },
    "updated": {
      "data": "2026-08-20T18:15:04.096124+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$mysql_connector/odbc",
        "oracle$PRODUCT$mysql_connector\\/odbc",
        "oracle$PRODUCT$mysql_connectors"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-125",
        "CWE-284"
      ],
      "providers": [
        "nvd",
        "redhat"
      ]
    }
  },
  "redhat": {
    "cpes": [],
    "created": "2026-08-18T21:03:26+00:00",
    "description": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC).   The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
      },
      "threat_severity": "Moderate"
    },
    "redhat_repo_path": "2026/CVE-2026-71084.json",
    "references": [
      "https://nvd.nist.gov/vuln/detail/CVE-2026-71084",
      "https://www.cve.org/CVERecord?id=CVE-2026-71084",
      "https://www.oracle.com/security-alerts/cspuaug2026.html"
    ],
    "title": "mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via unauthenticated local access",
    "updated": "2026-08-18T21:03:26+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-125"
    ]
  }
}
Enrichment data
View JSON API Download JSON