CVE-2026-22015 is a confidentiality vulnerability in Oracle MySQL Server's Information Schema component affecting versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0. The vulnerability allows a low-privileged authenticated attacker with network access to read a subset of sensitive data from affected MySQL instances. The vulnerability presents a medium-severity risk with a CVSS 3.1 base score of 4.3, characterized by network accessibility, low attack complexity, and requirement for low-level user privileges. While the impact is limited to unauthorized data disclosure with no integrity or availability impacts, the ease of exploitation and minimal prerequisites make it a notable concern for organizations running vulnerable MySQL versions. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.00027 indicating minimal real-world exploitation activity. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is widely available. Community attention remains low, making this a lower-priority threat compared to higher-severity vulnerabilities, though patching should still be scheduled as part of routine MySQL maintenance updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.8CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Apr 14, 2026