Summary
A denial-of-service vulnerability in Oracle MySQL Server's Pluggable Authentication component affects versions 9.0.0 to 9.5.0. The flaw can be triggered by a high-privileged attacker with network access, causing partial outages of MySQL Server. There is no confidentiality or integrity impact; patches are available via Oracle's January 2026 CPU. (CVE-2026-3547 / EUVD-2026-3547).
Why Planned Fix?
1/6Exploitation Details
Partial denial of service of MySQL Server; attacker with high privileges and network access can cause availability disruption.
Affected Software
| Product | Affected Versions |
|---|---|
| MySQL Server | 9.0.0-9.5.0 |
MySQL Server is an open-source relational database management system developed by Oracle that supports SQL-based data storage and retrieval; widely used in enterprise environments.
Affected ComponentMySQL Server Pluggable Authentication component (Pluggable Auth)
MySQL Server Pluggable Authentication component (Pluggable Auth)
Affected Endpoints(1)https://dev.mysql.com/doc/mysql-8.0-en/pluggable-authentication.html
Not available
Not available
Not available
Probability of exploitation in the next 30 days
Worse than 15% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L)
Affected Software (CPE) (1)
- •cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | https://nvd.nist.gov/vuln/detail/CVE-2026-21965 |
| www.cvedetails.com | https://www.cvedetails.com/cve/CVE-2026-21965/ |
| www.oracle.com | https://www.oracle.com/security-alerts/cpujan2026.html |
| feedly.com | https://feedly.com/cve/CVE-2026-21965 |
Priority History
Initial analysis