CVE-2026-22002General(oracle / mysql_server)

LOWCVSS 4.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mysql_server

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • False Positive: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-27); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
mysql_server

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-27: 1Mentions · 2026-08-04: 1Mentions · 2026-08-05: 1PoC Mentioned / Linked · 2026-08-04: 1Technical Details · 2026-04-27: 1Technical Details · 2026-08-04: 104-2708-0408-05
Signal classification2 categories
General
266.7%
False Positive
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-271
General1
2026-08-041
False Positive1
2026-08-051
General1
Full discourse3 posts
  • Andre Gironda@AndreGironda
    False Positive

    @cyber_advising Did you get your CVEs confused? I do see VNC Auth Bypass POC -- https://github.com/George0Papasotiriou/CVE-2026-22002-VNC-Authentication-Bypass-via-Protocol-Version-Confusion -- but I instead see CVE-2026-22002 is an unspecified vulnerability in the Optimizer component of Oracle MySQL

    Post summary

    The user points out that the linked VNC Auth Bypass PoC does not match CVE‑2026‑22002, which actually refers to an unspecified Oracle MySQL optimizer issue, effectively debunking the misidentified vulnerability.

    00034317
    3.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-22002 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0… https://www.cve.org/CVERecord?id=CVE-2026-22002

    Post summary

    The entry lists CVE-2026-22002 as impacting specific MySQL server versions and the Optimizer component, but it does not provide exploit code, patch information, or evidence of active attacks.

    00010134
    57.3K followersView on X
  • Sudionik vremena@TimeIsNow2000
    General

    @cyber_advising Get your shit together https://nvd.nist.gov/vuln/detail/CVE-2026-22002

    Post summary

    The tweet simply references CVE-2026-22002 via a link but provides no further details or actionable information.

    0000092
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclemysql_server---

Explore more