NONE · 0

CVE-2026-61828

Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the M...

Vulnerability Description

Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in as the root user without a password when the service is used with mysql or percona-server. This issue is fixed in the 25.11 and 26.05.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-61828?

CVE-2026-61828 is a documented vulnerability. Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the M...

How severe is CVE-2026-61828?

CVSS scoring is not yet available for CVE-2026-61828. Check NVD for updates.

Is there a patch for CVE-2026-61828?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.