Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22017

22
FAUCET Score

CVE-2026-22017 is a denial-of-service vulnerability in Oracle MySQL Server's Optimizer component affecting versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. The flaw allows low-privileged attackers with network access to trigger server hangs or crashes through multiple protocols, completely disabling the affected MySQL instance. This represents an availability-focused threat rather than a confidentiality or integrity concern. The vulnerability carries a CVSS 3.1 base score of 6.5 (Medium severity) with a network attack vector and low complexity, requiring only low-level privileges and no user interaction. The attack is easily exploitable, making it accessible to relatively unsophisticated threat actors who can establish network connectivity to MySQL servers. The primary impact is complete denial of service through frequent, repeatable crashes. From an exploitation standpoint, CVE-2026-22017 does not appear to be actively exploited in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and maintains an EPSS score of 0.0004, indicating minimal real-world exploitation activity to date. Current community attention appears limited, suggesting this remains a lower-priority threat compared to actively exploited vulnerabilities, though organizations running affected MySQL versions should still apply patches to prevent potential future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, <= 8.0.45CPE matchmatch criteria
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
>= 8.4.0, <= 8.4.8CPE matchmatch criteria
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
>= 9.0.0, <= 9.6.0CPE matchmatch criteria
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 29th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: azl3 mysql 8.0.45-2 on Azure Linux 3.0Fixed in: 8.0.46-1
microsoftpatch availablevia msrc
Product: 21156-17084Fixed in: 8.0.46-1
microsoftpatch availablevia msrc
Product: cbl2 mysql 8.0.45-3 on CBL Mariner 2.0Fixed in: 8.0.46-1
microsoftpatch availablevia msrc
Product: 21155-17086Fixed in: 8.0.46-1
ubuntupatch availablevia ubuntu_usn
Product: mysql-8.0 (noble)Fixed in: 8.0.46-0ubuntu0.24.04.2
ubuntupatch availablevia ubuntu_usn
Product: mysql-8.0 (jammy)Fixed in: 8.0.46-0ubuntu0.22.04.2
ubuntupatch availablevia ubuntu_usn
Product: mysql-8.4 (questing)Fixed in: 8.4.9-0ubuntu0.25.10.1
ubuntupatch availablevia ubuntu_usn
Product: mysql-8.4 (resolute)Fixed in: 8.4.9-0ubuntu0.26.04.1
oraclevendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

ubuntuUSN-8363-1

MySQL vulnerabilities

Jun 2, 2026
microsoft2026-Apr/CVE-2026-22017Moderate

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Apr 14, 2026

References

oracle.com / security-alerts/cpuapr2026.html
Vendor Advisory