CVE-2026-21936
MySQL vulnerability analysis and mitigation

Overview

CVE-2026-21936 is a Denial of Service vulnerability in the InnoDB component of Oracle MySQL Server. It affects MySQL Server versions 8.0.0–8.0.44, 8.4.0–8.4.7, and 9.0.0–9.5.0, as well as MySQL Cluster across the same version ranges (including 7.6.0–7.6.36). The vulnerability was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. It carries a CVSS v3.1 base score of 4.9 (Medium) (Oracle CPU Jan 2026).

Technical details

The vulnerability resides in the InnoDB storage engine component of MySQL Server. A high-privileged attacker with network access via multiple protocols can send crafted requests that cause the MySQL Server process to hang or crash repeatedly, resulting in a complete Denial of Service condition. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (e.g., a valid administrative database account). No specific CWE classification has been publicly assigned, and Oracle has not disclosed the precise internal root cause beyond the InnoDB component scope (Oracle CPU Jan 2026).

Impact

Successful exploitation results exclusively in an availability impact — specifically, the unauthorized ability to cause a hang or frequently repeatable crash (complete Denial of Service) of the MySQL Server. There is no confidentiality or integrity impact associated with this vulnerability. Affected deployments include MySQL Server and MySQL Cluster instances across multiple major version branches, meaning database-dependent applications and services could experience sustained outages if exploited (Oracle CPU Jan 2026).

Mitigation and workarounds

Oracle has released patches for this vulnerability as part of the January 2026 Critical Patch Update. Users should upgrade MySQL Server to versions beyond 8.0.44 (i.e., 8.0.45+), 8.4.7 (i.e., 8.4.8+), or 9.5.0 (i.e., 9.5.1+) depending on their current version branch. As a temporary measure, restricting network access to the MySQL Server to only trusted administrative users can reduce exposure. Oracle strongly recommends applying the CPU patches without delay rather than relying on network-level workarounds as a long-term solution (Oracle CPU Jan 2026). IBM has also released a patch for affected IBM API Connect deployments (IBM Advisory).

Community reactions

The vulnerability received routine coverage as part of Oracle's January 2026 CPU, which addressed 337 security patches across Oracle product families. Linux distribution vendors including Red Hat, AlmaLinux, Rocky Linux, and Oracle Linux issued downstream advisories and errata (RHSA-2026:4162, RHSA-2026:4828, RHSA-2026:5580, RHSA-2026:5640, RHSA-2026:6391) to address this and related MySQL vulnerabilities. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-21936 has been identified, consistent with its medium severity and high privilege requirement (Oracle CPU Jan 2026).

Additional resources


SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61109MEDIUM6.5
  • MySQL logoMySQL
  • mysql8.4-errmsg
NoYesJul 21, 2026
CVE-2026-61108MEDIUM6.5
  • MySQL logoMySQL
  • mariadb
NoNoJul 21, 2026
CVE-2026-61144MEDIUM4.9
  • MySQL logoMySQL
  • mariadb1011
NoNoJul 21, 2026
CVE-2026-61128MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61096LOW2.9
  • MySQL logoMySQL
  • mysql:8.4::mysql-common
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management