Junglewise Threat Intelligence

CVE-2026-46861: Oracle MySQL NDB Cluster improper access control in NDB Operator

CVE-2026-46861 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Vendors: Oracle Corporation, Oracle.

Executive brief

A critical vulnerability exists in the Oracle MySQL NDB Operator, a component used to manage high-availability database clusters. A low-privileged attacker can exploit this flaw over a network to gain full access to sensitive database information or modify critical data. This could lead to a complete compromise of the database cluster and potentially impact other connected business systems.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the NDB Operator component of Oracle MySQL NDB Cluster. It is exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (Status: Changed in CVSS), meaning an exploit can impact resources beyond the NDB Cluster itself. Successful exploitation allows for the unauthorized creation, deletion, or modification of all cluster-accessible data, as well as full confidentiality impact. Affected versions include the 8.0, 8.4, and 9.0 release streams.

Affected products

  • Oracle MySQL NDB Cluster 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References