Junglewise Threat Intelligence

CVE-2026-47023: Oracle MySQL Server and MySQL Cluster denial of service in Replication

CVE-2026-47023 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Replication component of Oracle MySQL Server and MySQL Cluster could allow an attacker to crash the database service. MySQL is a widely used database system for storing and managing business data; an exploit would result in a complete denial of service, making data unavailable to applications and users. To carry out this attack, the individual would already need high-level administrative privileges on the network.

Technical details

A vulnerability exists in the Replication component of Oracle MySQL Server and MySQL Cluster. The flaw is easily exploitable by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to trigger a hang or a frequently repeatable crash, resulting in a complete denial of service (DoS) of the affected database instance. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users are advised to consult the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats