CVE-2026-61828

Source
https://cve.org/CVERecord?id=CVE-2026-61828
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61828.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61828
Aliases
  • GHSA-6qxx-6rg8-c4p8
Published
2026-07-15T14:52:35Z
Modified
2026-08-12T03:51:13Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`
Details

Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in as the root user without a password when the service is used with mysql or percona-server. This issue is fixed in the 25.11 and 26.05.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-276"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61828.json"
}
References

Affected packages

Git / github.com/nixos/nixpkgs

Affected ranges

Type
GIT
Repo
https://github.com/nixos/nixpkgs
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "25.11"
        },
        {
            "introduced": "26.05-beta"
        },
        {
            "fixed": "26.05"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1
0.13
0.14
0.2
0.3
0.4
15.*
15.09-beta
18.*
18.03-beta
18.09-beta
21.*
21.11-pre
23.*
23.05-pre
23.11-beta
23.11-pre
24.*
24.05-pre
24.11-pre
25.*
25.11
25.11-beta
25.11-pre
26.*
26.05
26.05-beta
26.05-pre
26.11-pre
Other
v192
v206
v208

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61828.json"