PT-2026-3712 · Oracle+1 · Oracle Mysql+1

Published

2026-01-20

·

Updated

2026-01-29

·

CVE-2026-21965

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 9.0.0 through 9.5.0
Description An issue exists in the MySQL Server product of Oracle MySQL, specifically within the Server: Pluggable Auth component. This allows a high-privileged attacker with network access, through multiple protocols, to cause a partial denial of service (partial DOS) of the MySQL Server.
Recommendations Update MySQL Server versions prior to 9.5.1.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-00703
CVE-2026-21965

Affected Products

Mysql Server
Oracle Mysql