Junglewise Threat Intelligence

CVE-2026-47052: Oracle MySQL InnoDB denial of service vulnerability

CVE-2026-47052 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the InnoDB component of Oracle MySQL Server and MySQL Cluster could allow an attacker to crash the database service. This issue affects the availability of the database, potentially leading to service outages for applications that rely on it. To exploit this, an attacker must already have high-level administrative privileges and network access to the database server.

Technical details

A vulnerability exists in the InnoDB storage engine component of Oracle MySQL Server and MySQL Cluster. The flaw allows a high-privileged attacker with network access via multiple protocols to trigger a denial-of-service (DoS) condition. Successful exploitation can result in a frequently repeatable crash or a complete hang of the MySQL instance. The vulnerability is classified as easily exploitable but requires 'High' privileges (PR:H), meaning the attacker must have significant existing access to the database environment. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats