Junglewise Threat Intelligence

CVE-2026-61828: NixOS nixpkgs insecure default authentication in MySQL services

CVE-2026-61828 · Severity: info · CVSS 8.5 · Published 2026-07-15

Executive brief

A security issue in the NixOS configuration for MySQL and Percona databases allows local users on a system to log in as the database administrator (root) without a password. This could allow an unprivileged user or a compromised web application on the same server to gain full control over the database, leading to the theft or destruction of sensitive data. The vulnerability stems from how the database is initialized by the operating system's package collection.

Technical details

A vulnerability exists in the NixOS 'services.mysql' module within nixpkgs where MySQL and Percona Server instances are initialized with insecure default authentication settings. Specifically, the root@localhost user is not automatically secured with socket-based authentication (auth_socket), allowing any local user—including unprivileged service accounts like web or CGI processes—to authenticate as the database root user without a password. This is classified as a CWE-276 (Incorrect Default Permissions) issue. The fix, introduced in versions 25.11 and 26.05, enforces 'auth_socket' authentication by default for the root user. Exploitation requires local access to the host but no special privileges.

Affected products

  • NixOS nixpkgs < 25.11, >= 26.05-beta < 26.05

Timeline

  • 2026-06-22: patched: Initial fix committed to nixpkgs master branch
  • 2026-07-15: disclosed: CVE-2026-61828 published
  • 2026-07-15: advisory: GitHub Security Advisory GHSA-6qxx-6rg8-c4p8 released

References