EIP-2026-103171
PRE-CVEMySQL 3.20.32/3.22.x/3.23.x - Null Root Password Weak Default Configuration (2)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103171. PoCs published by st0ic.
AI-analyzed exploit summary This code is a MySQL Class C IP scanner that identifies vulnerable MySQL daemons with default root credentials (no password). It attempts to log in and dump user credentials from the mysql.user table.
Description
MySQL 3.20.32/3.22.x/3.23.x - Null Root Password Weak Default Configuration (2)
Exploits (1)
exploitdb
SCANNER
VERIFIED
by st0ic · cremotelinux
https://www.exploit-db.com/exploits/21726
This code is a MySQL Class C IP scanner that identifies vulnerable MySQL daemons with default root credentials (no password). It attempts to log in and dump user credentials from the mysql.user table.
Classification
Scanner 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target:
MySQL (Windows binary release with default configuration)
No auth needed
Prerequisites:
Network access to target MySQL servers · MySQL default port (3306) open
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026