Home / Security / Advisories / NTAP-20260925-0029
NTAP-20260925-0029 — CVE-2026-34317 MySQL Shell Vulnerability in NetApp Products
Published 2026-09-25 · Updated 2026-09-25 · Status: Interim · Exploitation: Public · Severity: MEDIUM 5.0 · ONTAP affected: No — other NetApp product
Product family: NetApp Console / BlueXP | other NetApp product | highest CVSS: 5.0
CVEs in this advisory
- CVE-2026-34317 — MEDIUM · CVSS 5.0 · site index
What the CVE records say
CVE-2026-34317 — Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).
Impact
Successful exploitation of this vulnerability could lead to Denial of Service (DoS).
Affected products
- NetApp Console Agent Container (mysql)
References
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2026