CVE-2026-27965 is a critical vulnerability affecting Vitess, a database clustering system for MySQL, specifically versions prior to 23.0.3 and 22.0.4. It allows an attacker with read/write access to the backup storage location to manipulate backup manifest files, leading to arbitrary code execution during backup restoration. This can grant unauthorized access to the production deployment environment, enabling data access and arbitrary command execution. Rated 9.9 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The EPSS score is very low, suggesting a low probability of exploitation in the wild. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion, with three mentions across GitHub and Bluesky.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 22.0.4CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:vitess:*:*:*:*:*:*:*:* | ||
>= 23.0.0, < 23.0.3CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:vitess:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vitess users with backup storage access can gain unauthorized access to production deployment environments
Feb 26, 2026Vitess users with backup storage access can gain unauthorized access to production deployment environments
Feb 10, 2026