CVE-2026-27965Disclosure(linuxfoundation / vitess)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. This can be used to provide that attacker with unintended/unauthorized access to the production deployment environment — allowing them to access information available in that environment as well as run any additional arbitrary commands there. Versions 23.0.3 and 22.0.4 contain a patch. Some workarounds are available. Those who intended to use an external decompressor then can always specify that decompressor command in the `--external-decompressor` flag value for `vttablet` and `vtbackup`. That then overrides any value specified in the manifest file. Those who did not intend to use an external decompressor, nor an internal one, can specify a value such as `cat` or `tee` in the `--external-decompressor` flag value for `vttablet` and `vtbackup` to ensure that a harmless command is always used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vitess

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-26); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
vitess

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-26: 3Mentions · 2026-03-03: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-03: 102-2603-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure3
2026-03-031
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27965 (CVSS:8.4, CRITICAL) is Analyzed. Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with..https://nvd.nist.gov/vuln/detail/CVE-2026-27965 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights CVE-2026-27965 as a critical vulnerability affecting Vitess versions prior to 23.0.3 and 22.0.4, noting its CVSS score of 8.4, but it does not provide PoC, exploit, patch, or active exploitation details.

    0000024
    173 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27965: Manifest Destiny: How Vitess Backups Became a Shell-Popping Paradise In the world of horizontal scaling, Vitess is the titan that keeps the likes of Slack and YouTube running. But even titans have Achilles' heels. CVE-2026-27965 expose... https://cvereports.com/reports/CVE-2026-27965

    Post summary

    The article announces the discovery of CVE-2026-27965 affecting Vitess backups, but provides no further technical or mitigation details.

    0000041
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27965 Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage locat… https://www.cve.org/CVERecord?id=CVE-2026-27965

    Post summary

    The CVE highlights a vulnerability in Vitess where read/write access to backup storage can be abused, but no PoC, exploit, or patch details are provided in the text.

    00000102
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27965 Arbitrary Code Execution in Vitess Backup Manifest via Storage Lo... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27965 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new CVE (CVE-2026-27965) for arbitrary code execution in Vitess backup manifests has been reported, with limited details provided.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationvitess---

Explore more