CVE-2026-34293 is a denial-of-service vulnerability affecting Oracle MySQL Server versions 8.0.0 through 8.0.45, specifically within the DML (Data Manipulation Language) component. The flaw allows high-privileged network attackers to trigger server hangs or repeated crashes, resulting in complete availability loss. The vulnerability presents a medium severity risk with a CVSS score of 4.9. It requires high-level privileges and network access but is easily exploitable with low attack complexity and no user interaction. The impact is limited to availability disruption with no effects on confidentiality or integrity. Exploitation appears minimal at this time. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, has an extremely low EPSS score of 0.00037, and shows inactive status on threat tracking lists. No widespread exploit code or active exploitation has been observed in the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026