Executive brief
A vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A highly privileged attacker could exploit this flaw to cause the database to hang or crash repeatedly. This would result in a complete denial of service, preventing applications and users from accessing critical data.
Technical details
This vulnerability is located in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial of service (DoS) flaw that can result in a frequently repeatable crash or a system hang. The attack vector is network-based via multiple protocols, but exploitation is considered difficult (High Attack Complexity) and requires High Privileges. Successful exploitation impacts the Availability of the service but does not compromise Confidentiality or Integrity. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed