CVE-2026-46863
Awaiting Analysis Awaiting Analysis - Queue
Denial of Service in Oracle MySQL Server

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are MySQL Server: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
oracle mysql_server From 8.4.0 (inc) to 8.4.9 (inc)
oracle mysql_server From 9.0.0 (inc) to 9.7.0 (inc)
oracle mysql_cluster From 8.0.11 (inc) to 8.0.46 (inc)
oracle mysql_cluster From 8.4.0 (inc) to 8.4.9 (inc)
oracle mysql_cluster From 9.0.0 (inc) to 9.7.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server's Connection Handling component. It affects multiple supported versions of MySQL Server and MySQL Cluster.

An unauthenticated attacker with network access via multiple protocols can exploit this vulnerability easily. Successful exploitation allows the attacker to cause the MySQL Server or MySQL Cluster to hang or crash repeatedly, resulting in a denial of service (DoS).

Impact Analysis

The primary impact of this vulnerability is on the availability of the MySQL Server or MySQL Cluster. An attacker can cause the server to hang or crash repeatedly, leading to a complete denial of service.

This means that legitimate users and applications relying on the database may experience interruptions, downtime, or loss of service until the issue is resolved.

Compliance Impact

The vulnerability allows an unauthenticated attacker to cause a denial of service (DoS) by hanging or crashing the MySQL Server or MySQL Cluster, impacting availability.

However, there is no information provided about impacts on confidentiality or integrity, which are critical for compliance with standards like GDPR or HIPAA.

Therefore, based on the available information, this vulnerability primarily affects availability but does not directly indicate a breach of data privacy or integrity requirements under common regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46863. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart