CVE-2026-34276 is a denial-of-service vulnerability in Oracle MySQL Server's Group Replication Plugin that affects versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. The flaw allows low-privileged attackers with network access to cause the MySQL Server to hang or crash repeatedly, completely disrupting service availability. The vulnerability has a CVSS 3.1 score of 6.5 (Medium severity) and requires minimal attack complexity with network accessibility. An attacker needs only low-level privileges and can exploit the flaw without user interaction through multiple network protocols, though the impact is limited to availability with no confidentiality or integrity compromise possible. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.0004 indicating very low probability of exploitation. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention remains minimal, suggesting this represents a lower-priority patching requirement compared to other disclosed vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.8CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026