OVERVIEW CVE-2026-34278 is a vulnerability in Oracle MySQL Server's Optimizer component affecting versions 8.0.0 through 8.0.45. The flaw allows attackers to trigger denial-of-service conditions through server hangs or repetitive crashes, compromising service availability. SEVERITY This vulnerability has a CVSS 3.1 base score of 4.9 (Medium severity) and requires high-level privileges to exploit. The attack vector is network-based with low complexity, meaning an authenticated administrator with network access can trigger the vulnerability without significant technical barriers. The impact is limited to availability disruption, with no effect on confidentiality or integrity of data. EXPLOITATION STATUS Current exploitation risk is minimal. The vulnerability carries an extremely low EPSS score of 0.00037, indicating minimal real-world exploitation activity. It is not included in the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation. Community attention remains low, reflected in the moderate FAUCET risk score of 31.0 out of 100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026