Junglewise Threat Intelligence

CVE-2026-60145: Oracle MySQL Server Optimizer denial of service

CVE-2026-60145 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Optimizer component of Oracle MySQL Server and MySQL Cluster could allow a high-privileged user to crash the database service. This results in a complete denial-of-service, making the database and any dependent applications unavailable. While the attack requires existing administrative-level access, it can be performed remotely over the network.

Technical details

A vulnerability exists in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster. The flaw is easily exploitable by a high-privileged attacker with network access via multiple protocols. A successful exploit allows the attacker to trigger a hang or a frequently repeatable crash, resulting in a complete denial-of-service (DoS) of the affected database instance. The vulnerability affects MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
  • 2026-07-21: disclosed

References

Related threats