Executive brief
A critical vulnerability exists in the Oracle MySQL NDB Operator, a component used to manage high-availability database clusters. A low-privileged attacker can exploit this flaw over a network to gain full access to sensitive database information or modify critical data. This could lead to a complete compromise of the database cluster and potentially impact other connected business systems.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the NDB Operator component of Oracle MySQL NDB Cluster. It is exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (Status: Changed in CVSS), meaning an exploit can impact resources beyond the NDB Cluster itself. Successful exploitation allows for the unauthorized creation, deletion, or modification of all cluster-accessible data, as well as full confidentiality impact. Affected versions include the 8.0, 8.4, and 9.0 release streams.
Affected products
- Oracle MySQL NDB Cluster 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published