CVE-2026-71079
Analyzed Analyzed - Analysis Complete

Denial of Service in MySQL Connector/ODBC

Vulnerability report for CVE-2026-71079, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-09-02

Assigner: Oracle

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-09-02
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle mysql_connector/odbc 26.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle MySQL Connectors, specifically affecting version 26.7.0. It allows a low-privileged attacker with network access to cause a denial of service (DOS) by repeatedly crashing or hanging the MySQL Connectors service. The impact is limited to availability, with no unauthorized data access or modification.

Detection Guidance

This vulnerability affects MySQL Connector/ODBC version 26.7.0. To detect it, check the installed version of MySQL Connector/ODBC on your system. Use commands like 'dpkg -l | grep mysql-connector-odbc' on Debian-based systems or 'rpm -qa | grep mysql-connector-odbc' on RPM-based systems to verify the version.

Impact Analysis

If you use MySQL Connectors version 26.7.0, an attacker could disrupt your database operations by causing frequent crashes or hangs. This could lead to downtime, loss of service, and potential data unavailability for applications relying on the connector.

Compliance Impact

This vulnerability primarily impacts availability, which could lead to service disruptions. While it does not directly cause data breaches, prolonged downtime may violate compliance requirements for data accessibility under regulations like GDPR or HIPAA, depending on the context of use.

Mitigation Strategies

Upgrade MySQL Connector/ODBC to a version unaffected by this vulnerability. Apply patches or updates from Oracle as soon as they become available. Monitor Oracle's security advisories for updates on this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71079. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart