Back

MEDIUM

mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via unauthenticated local access

Published Aug 18, 2026

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).

Affected products

Remediation

Red Hat statement

This Moderate severity flaw in `mysql-connector-odbc` allows an unauthenticated attacker with local logon access to the system to cause a complete denial of service and gain unauthorized read access to a subset of data. The local attack vector limits the immediate remote exploitability, but successful exploitation can significantly impact system availability and data confidentiality.

Red Hat mitigation

Since this vulnerability requires local logon access, ensure that only trusted users have interactive access to systems running `mysql-connector-odbc`. If the `mysql-connector-odbc` package is not actively used, consider removing it to eliminate the attack surface.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner oracle
Published Aug 18, 2026
Updated Aug 19, 2026
Reserved Aug 4, 2026
CISA Vulnrichment
Updated Aug 19, 2026
NVD
Status Analyzed
Modified Sep 2, 2026
Red Hat
Severity Moderate
Public date Aug 18, 2026