<Vulnerability name="CVE-2026-71084">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-18T21:03:26</PublicDate>
    <Bugzilla id="2519277" url="https://bugzilla.redhat.com/show_bug.cgi?id=2519277" xml:lang="en:us">
mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via unauthenticated local access
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-125</CWE>
    <Details xml:lang="en:us" source="Mitre">
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC).   The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in mysql-connector-odbc. An unauthenticated attacker with local logon access to the infrastructure where MySQL Connectors executes can exploit this vulnerability. This can lead to a complete denial of service (DoS) by causing the component to crash repeatedly. Additionally, the attacker may gain unauthorized read access to a subset of data accessible by MySQL Connectors.
    </Details>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>mysql-connector-odbc</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>mysql-connector-odbc</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-71084
https://nvd.nist.gov/vuln/detail/CVE-2026-71084
https://www.oracle.com/security-alerts/cspuaug2026.html
    </References>
</Vulnerability>