A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-35237

CVE-2026-35237: Oracle MySQL Server DOS Vulnerability

CVE-2026-35237 is a denial of service flaw in Oracle MySQL Server InnoDB component that allows attackers to crash the database. This article covers technical details, affected versions, impact, and mitigation.

Published: April 23, 2026

CVE-2026-35237 Overview

CVE-2026-35237 is a denial of service vulnerability affecting the InnoDB storage engine component of Oracle MySQL Server. This improper access control flaw (CWE-284) allows a high-privileged attacker with network access to cause a complete denial of service condition against MySQL Server instances. The vulnerability is classified as easily exploitable and can be triggered via multiple network protocols, resulting in a hang or frequently repeatable crash of the database server.

Critical Impact

Successful exploitation enables attackers with administrative privileges to completely disrupt MySQL Server availability, causing service outages for all dependent applications and services.

Affected Products

  • Oracle MySQL Server 8.0.0 through 8.0.45
  • Oracle MySQL Server 8.4.0 through 8.4.8
  • Oracle MySQL Server 9.0.0 through 9.6.0

Discovery Timeline

  • April 21, 2026 - CVE-2026-35237 published to NVD
  • April 23, 2026 - Last updated in NVD database

Technical Details for CVE-2026-35237

Vulnerability Analysis

This vulnerability resides in the InnoDB storage engine, MySQL's default transactional storage engine. The flaw is categorized under CWE-284 (Improper Access Control), indicating that the vulnerability stems from insufficient validation or control mechanisms within the InnoDB component.

The attack requires high privileges but low complexity to execute. An attacker with administrative database credentials can exploit this vulnerability remotely over the network using standard MySQL protocols. The impact is limited to availability—there is no compromise of confidentiality or integrity. However, the availability impact is complete, meaning successful exploitation results in total loss of database service availability.

Root Cause

The root cause stems from improper access control within the InnoDB storage engine component. When certain operations are performed by a privileged user, the engine fails to properly handle the request, leading to resource exhaustion or an unrecoverable error state that causes the MySQL Server process to hang or crash.

Attack Vector

The attack is network-based and can be executed via multiple protocols supported by MySQL Server. An attacker requires:

  1. Valid high-privileged credentials (administrative access) to the MySQL Server
  2. Network connectivity to the target MySQL instance
  3. Ability to execute specific operations that trigger the vulnerable code path in InnoDB

The vulnerability does not require user interaction and affects only the vulnerable system (unchanged scope). While the attack requires elevated privileges, organizations with compromised administrative credentials or malicious insiders are at risk.

Detection Methods for CVE-2026-35237

Indicators of Compromise

  • Unexpected MySQL Server crashes or hangs, particularly when administrative operations are performed
  • Repeated crash recovery events in MySQL error logs related to InnoDB operations
  • Unusual connection patterns from privileged accounts followed by service interruptions
  • InnoDB-specific error messages in logs preceding server unresponsiveness

Detection Strategies

  • Monitor MySQL error logs for crash patterns and InnoDB-related errors using SIEM integration
  • Configure alerting on MySQL Server process terminations or restarts outside maintenance windows
  • Implement database activity monitoring (DAM) to track privileged user operations
  • Set up health checks that detect prolonged query hangs or connection timeouts

Monitoring Recommendations

  • Enable MySQL Server crash dumps and error logging for forensic analysis
  • Deploy real-time monitoring of MySQL availability and response times
  • Track authentication events for privileged accounts and correlate with service disruptions
  • Monitor system resources (CPU, memory) for anomalies preceding crashes

How to Mitigate CVE-2026-35237

Immediate Actions Required

  • Apply the Oracle Critical Patch Update (CPU) for April 2026 immediately
  • Review and restrict network access to MySQL Server instances using firewall rules
  • Audit accounts with high privileges and enforce principle of least privilege
  • Implement strong authentication and credential management for administrative accounts

Patch Information

Oracle has addressed this vulnerability in the April 2026 Critical Patch Update. Administrators should upgrade to patched versions:

  • MySQL Server 8.0.46 or later
  • MySQL Server 8.4.9 or later
  • MySQL Server 9.6.1 or later

For detailed patch information and download links, refer to the Oracle Critical Patch Update April 2026.

Workarounds

  • Restrict network access to MySQL Server to trusted hosts and networks only
  • Implement database firewall rules to limit administrative operations from specific IP addresses
  • Enable MySQL audit logging to detect and investigate suspicious privileged activity
  • Consider placing MySQL instances behind a VPN or private network segment
bash
# Example: Restrict MySQL access to trusted hosts via firewall
iptables -A INPUT -p tcp --dport 3306 -s 10.0.0.0/8 -j ACCEPT
iptables -A INPUT -p tcp --dport 3306 -j DROP

# Example: Review privileged users in MySQL
mysql -e "SELECT user, host FROM mysql.user WHERE Super_priv='Y' OR Create_user_priv='Y';"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechOracle Mysql Server

  • SeverityMEDIUM

  • CVSS Score4.9

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-284
  • Vendor Resources
  • Oracle Critical Patch Update April 2026
  • Related CVEs
  • CVE-2026-35235: Oracle MySQL Server DoS Vulnerability

  • CVE-2026-35234: Oracle MySQL Server DoS Vulnerability

  • CVE-2026-34308: Oracle MySQL Server DoS Vulnerability

  • CVE-2026-34304: Oracle MySQL Server DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English