CVE-2026-46863
MySQL vulnerability analysis and mitigation

Overview

CVE-2026-46863 is a Denial of Service vulnerability in the Server: Connection Handling component of Oracle MySQL Server and MySQL Cluster. It was disclosed on June 16, 2026, as part of Oracle's Critical Security Patch Update (CSPU). Affected versions include MySQL Server 8.4.0–8.4.9 and 9.0.0–9.7.0, and MySQL Cluster 8.0.11–8.0.46, 8.4.0–8.4.9, and 9.0.0–9.7.0. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory). The vulnerability was reported to Oracle by researchers 4ra1n, pyn3rd, and unam4 (Oracle Advisory).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), residing in the connection handling subsystem of MySQL Server and MySQL Cluster. An unauthenticated remote attacker can exploit this flaw by sending specially crafted requests over multiple supported protocols, causing the server to consume excessive resources and ultimately hang or crash. No authentication or user interaction is required, and attack complexity is low, making it straightforward to trigger. The associated CAPEC patterns include CAPEC-147 (XML Ping of the Death) and CAPEC-492 (Regular Expression Exponential Blowup), suggesting the root cause may involve malformed or resource-intensive input during connection establishment (Oracle Advisory).

Impact

Successful exploitation results in a complete denial of service — the MySQL Server or MySQL Cluster instance will hang or crash in a frequently repeatable manner, causing sustained service unavailability. There is no confidentiality or integrity impact; the vulnerability is purely an availability issue. Given that MySQL is commonly used as a backend for critical applications, a successful attack could disrupt dependent services and applications at scale (Oracle Advisory).

Mitigation and workarounds

Oracle has released patches addressing this vulnerability as part of the June 2026 Critical Security Patch Update. Administrators should upgrade MySQL Server to a version beyond 8.4.9 or 9.7.0, and MySQL Cluster to a version beyond 8.0.46, 8.4.9, or 9.7.0, depending on their deployment branch. As interim mitigations, apply network segmentation to restrict MySQL port access (default TCP 3306/33060) to trusted hosts only, and implement rate limiting on connection attempts to reduce exposure. Oracle strongly recommends applying patches as soon as possible rather than relying on network-level workarounds (Oracle Advisory).

Community reactions

Ubuntu issued security notices USN-8457-1 and USN-8457-2 addressing this and related MySQL vulnerabilities for Ubuntu users, indicating downstream Linux distribution uptake of the patch (Ubuntu USN-8457-1, Ubuntu USN-8457-2). Tenable published multiple Nessus detection plugins (IDs 321532, 321533, 321535, 321537, 321654, 322263) to identify vulnerable systems. No significant public researcher commentary or social media discussion has been observed beyond standard patch tracking.

Additional resources


SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61109MEDIUM6.5
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoYesJul 21, 2026
CVE-2026-61108MEDIUM6.5
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61144MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_cluster
NoNoJul 21, 2026
CVE-2026-61128MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61096LOW2.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management