Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27965

33
FAUCET Score

CVE-2026-27965 is a critical vulnerability affecting Vitess, a database clustering system for MySQL, specifically versions prior to 23.0.3 and 22.0.4. It allows an attacker with read/write access to the backup storage location to manipulate backup manifest files, leading to arbitrary code execution during backup restoration. This can grant unauthorized access to the production deployment environment, enabling data access and arbitrary command execution. Rated 9.9 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The EPSS score is very low, suggesting a low probability of exploitation in the wild. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion, with three mentions across GitHub and Bluesky.

Impacted Technologies

VendorProductVersion(s)CPE
< 22.0.4CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:vitess:*:*:*:*:*:*:*:*
>= 23.0.0, < 23.0.3CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:vitess:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.4HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 29th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 vitess 17.0.7-14 on CBL Mariner 2.0Fixed in: 17.0.7-15
microsoftpatch availablevia msrc
Product: azl3 vitess 19.0.4-9 on Azure Linux 3.0Fixed in: 19.0.4-8
microsoftpatch availablevia msrc
Product: azl3 vitess 19.0.4-7 on Azure Linux 3.0Fixed in: 19.0.4-8
microsoftpatch availablevia msrc
Product: 20946-17086Fixed in: 17.0.7-15
microsoftpatch availablevia msrc
Product: 20968-17084Fixed in: 19.0.4-8
microsoftpatch availablevia msrc
Product: 17547-17084Fixed in: 19.0.4-8

Vendor Advisories (2)

goGHSA-8g8j-r87h-p36xhigh

Vitess users with backup storage access can gain unauthorized access to production deployment environments

Feb 26, 2026
microsoft2026-Feb/CVE-2026-27965Important

Vitess users with backup storage access can gain unauthorized access to production deployment environments

Feb 10, 2026

References

github.com / vitessio/vitess/commit/4c0173293907af9cb942a6683c465c3f1e9fdb5c
Patch
github.com / vitessio/vitess/issues/19459
Issue Tracking
github.com / vitessio/vitess/pull/19460
Issue TrackingPatch
github.com / vitessio/vitess/security/advisories/GHSA-8g8j-r87h-p36x
MitigationPatchVendor Advisory