CVE-2026-34271: Medium severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle MySQL - Group Replication Pluginfrom your environment.Uninstall or remove the Group Replication Plugin from MySQL Server instances where it is not needed.
- Configuration
If Group Replication is not required, disable the Group Replication Plugin on affected MySQL Server instances to remove the vulnerable component from operation.
MySQL Server (Group Replication Plugin) group_replication_plugin_enabled = false - Compensating control
Restrict network access to affected MySQL Servers to trusted hosts only (use firewall rules, ACLs, or network segmentation) and block or limit the protocols/ports that are not required, to prevent remote exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34271?
CVE-2026-34271 is considered an easily exploitable vulnerability that may allow low privileged attackers to compromise MySQL Server instances.
How do I fix CVE-2026-34271?
To fix CVE-2026-34271, upgrade to versions of MySQL Server beyond 8.0.45, 8.4.8, or 9.6.0.
Which MySQL Server versions are affected by CVE-2026-34271?
Affected MySQL Server versions include 8.0.0 to 8.0.45, 8.4.0 to 8.4.8, and 9.0.0 to 9.6.0.
What types of access are required to exploit CVE-2026-34271?
Exploitation of CVE-2026-34271 requires low privileged network access via multiple protocols.
Who is affected by CVE-2026-34271?
Organizations using vulnerable versions of Oracle MySQL Server are at risk due to CVE-2026-34271.