CVE-2026-71073: Medium severity Oracle MySQL Connectors (Connector/ODBC) vulnerability
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle MySQL MySQL Connectors (Connector/ODBC)to a version that resolves this vulnerability.Fixed in 26.7.0
Event History
Frequently Asked Questions
Who is exposed to exploitation of this issue?
Systems are exposed where the affected Connector/ODBC version 26.7.0 is executing and an attacker can log on to that infrastructure. The attack is local rather than network-based.
Does exploitation require credentials or user interaction?
The attacker does not need privileges, but must have logon access to the infrastructure where MySQL Connectors executes. Exploitation also requires interaction by a person other than the attacker.
What is the expected impact if exploited?
A successful attack can cause MySQL Connectors to hang or crash repeatedly, resulting in a complete denial of service. The provided CVSS vector indicates no confidentiality or integrity impact.