Junglewise Threat Intelligence

CVE-2026-47008: Oracle MySQL InnoDB denial of service

CVE-2026-47008 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the InnoDB component of Oracle MySQL Server and MySQL Cluster can allow an authorized user to crash the database service. This results in a denial-of-service condition, making the database and any dependent applications unavailable to users. While the attack requires high-level administrative privileges, it can be executed remotely over the network.

Technical details

A denial-of-service vulnerability exists in the InnoDB storage engine component of Oracle MySQL Server and MySQL Cluster. The flaw allows a high-privileged attacker with network access via multiple protocols to trigger a hang or a frequently repeatable crash of the server. The vulnerability is classified as easily exploitable but requires 'High' privileges (PR:H) for successful execution. Affected versions include MySQL Server and MySQL Cluster 9.7.0 through 9.7.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.

References

Related threats