CVE-2026-61828
HIGHnixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`
Title source: cnaDescription
Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in as the root user without a password when the service is used with mysql or percona-server. This issue is fixed in the 25.11 and 26.05.
References (7)
Core 7
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/NixOS/nixpkgs/security/advisories/GHSA-6qxx-6rg8-c4p8
X_Refsource_Misc x_refsource_misc
https://github.com/NixOS/nixpkgs/pull/534254
X_Refsource_Misc x_refsource_misc
https://github.com/NixOS/nixpkgs/pull/534482
X_Refsource_Misc x_refsource_misc
https://github.com/NixOS/nixpkgs/pull/534484
X_Refsource_Misc x_refsource_misc
https://github.com/NixOS/nixpkgs/commit/3f68d7ad2a6865ff8b4910d89f173d7258bad8dd
X_Refsource_Misc x_refsource_misc
https://github.com/NixOS/nixpkgs/commit/4aed47116a8734922763cd8f477467b0a0bcd6d7
X_Refsource_Misc x_refsource_misc
https://github.com/NixOS/nixpkgs/commit/f8ee41468a7a8f9ed3a8cc7d017151c2ca6f90b5
Scores
CVSS v4
8.5
EPSS
0.0011
EPSS Percentile
1.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (2)
NixOS/nixpkgs
< 25.11
NixOS/nixpkgs
>= 26.05-beta, < 26.05
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026