CVE-2026-27969Disclosure(linuxfoundation / vitess)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation vitess systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also added to the manifest and backup contents — are written to any accessible location on restore. This is a common path traversal security issue. This can be used to provide that attacker with unintended/unauthorized access to the production deployment environment — allowing them to access information available in that environment as well as run any additional arbitrary commands there. Versions 23.0.3 and 22.0.4 contain a patch. No known workarounds are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vitess

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-02-26); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Products
vitess

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-02-26: 3Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 102-2602-2702-2803-0203-03
Signal classification3 categories
Disclosure
444.4%
Patch
333.3%
General
222.2%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure2Patch1
2026-02-272
Disclosure1General1
2026-02-281
Patch1
2026-03-022
Disclosure1Patch1
2026-03-031
General1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Vitess patches critical flaws (CVE-2026-27969 & 27965) where poisoned backup manifests lead to path traversal and RCE during restoration. #Vitess #DatabaseSecurity #CyberSecurity #InfoSec #CloudNative #MySQL #BackupAndRecovery #Vulnerability https://securityonline.info/critical-backup-flaws-expose-vitess-environments-to-complete-takeover/

    Post summary

    Vitess has released patches for CVE‑2026‑27969 and CVE‑2026‑27965, which involve path traversal and remote code execution via poisoned backup manifests during restoration.

    11011260
    10.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Vitess path traversal flaw (CVE-2026-27969) lets attackers write files to arbitrary locations via backup restore! Affects <22.0.4, 23.0.0 – 23.0.3. Patch now & lock down backup storage. 🔒 https://radar.offseq.com/threat/cve-2026-27969-cwe-22-improper-limitation-of-... https://t.co/BFiVSvrc1L

    Post summary

    The tweet alerts to a critical path traversal vulnerability in Vitess (CVE-2026-27969) that permits arbitrary file writes through backup restore, and urges users to apply the patch and secure backup storage.

    0001071
    270 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27969 (CVSS:9.3, HIGH) is Analyzed. Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with..https://nvd.nist.gov/vuln/detail/CVE-2026-27969 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27969, noting its high severity and affected Vitess versions, but provides no evidence of exploitation, PoC, or mitigation.

    0000026
    173 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @the_yellow_fall Backup-as-attack-vector is underrated. Poisoned manifest → path traversal → RCE during restore means the moment you think you're recovering, you're actually being compromised. Both CVEs now on VulnTracker: http://vulntracker.io/cves/CVE-2026-27969

    Post summary

    The post describes a path traversal flaw in backup manifests that can lead to remote code execution during restore, with the CVE now listed on VulnTracker.

    0000045
    361 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical vulnerability (CVE-2026-27969) in `Vitess` allows arbitrary file writes on restore for users with backup storage access. Update to version 0.23.3 or later. #Vitess #DatabaseSecurity #CVE https://www.pulsepatch.io/posts/cve-2026-27969-vitess-arbitrary-file-write-restore

    Post summary

    The post announces a critical Vitess vulnerability (CVE-2026-27969) that permits arbitrary file writes during restore, and advises updating to version 0.23.3 or later.

    0000043
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-27969 - High Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) c... https://www.thehackerwire.com/vulnerability/CVE-2026-27969/ https://t.co/Z9TViLfsoe

    Post summary

    The tweet highlights a high‑severity vulnerability in Vitess affecting pre‑23.0.3 and pre‑22.0.4 releases, but does not provide further details on exploitation, patching, or PoC.

    0000032
    119 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27969: Vitess Path Traversal via Backup Manifest Manipulation A critical path traversal vulnerability exists in the Vitess `builtinbackupengine` component, specifically within the backup restoration workflow. The flaw arises from improper val... https://cvereports.com/reports/CVE-2026-27969

    Post summary

    The text announces CVE-2026-27969, a path traversal flaw in Vitess's builtinbackupengine, but does not provide PoC, exploit, or patch details.

    0000041
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27969 Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage locat… https://www.cve.org/CVERecord?id=CVE-2026-27969

    Post summary

    CVE-2026-27969 impacts Vitess versions prior to 23.0.3 and 22.0.4, allowing users with read/write access to backup storage to exploit the vulnerability.

    00000127
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27969 Path Traversal in Vitess Backup Storage Leading to Unauth... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27969 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A path traversal vulnerability in Vitess backup storage (CVE-2026-27969) is disclosed, but no PoC, exploit, patch, or active exploitation details are provided.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationvitess---

Explore more