PT-2026-3712 · Oracle+1 · Mysql Server+1

CVE-2026-21965

·

Published

2026-01-20

·

Updated

2026-01-29

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 9.0.0 through 9.5.0
Description An issue exists in the MySQL Server product of Oracle MySQL, specifically within the Server: Pluggable Auth component. This allows a high-privileged attacker with network access, through multiple protocols, to cause a partial denial of service (partial DOS) of the MySQL Server.
Recommendations Update MySQL Server versions prior to 9.5.1.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00703
CVE-2026-21965

Affected Products

Mysql Server
Oracle Mysql