logo

New MySQL-Related Default Insecurity Affects 7500+ Apps

ID: fe247aac-b369-58da-abc9-5282c778f9bb

STIX ID: report--fe247aac-b369-58da-abc9-5282c778f9bb

Feed Name: Censys Blog

Threat Score
50/100

Date Published: 2019-08-21

Date Updated: 2026-04-27

...
...

Censys published findings that SphinxSearch's insecure default configuration exposes the MySQL-compatible port 9306 with no authentication, enabling authentication bypass and potential data leakage; their Internet scan identified 7,576 affected instances (mostly in Russia and the US) and the recommended remediation is to bind the listener to localhost or place a host firewall in front of the service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.