Junglewise Threat Intelligence

CVE-2026-60163: Oracle MySQL Group Replication Plugin takeover vulnerability

CVE-2026-60163 · Severity: high · CVSS 8.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Group Replication component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. An attacker who has already gained access to the underlying server infrastructure can exploit this flaw to take full control of the database. This could lead to the theft of sensitive customer data, unauthorized modification of records, or a complete shutdown of database services.

Technical details

A vulnerability in the Server: Group Replication Plugin component of Oracle MySQL Server and MySQL Cluster allows for a complete takeover of the affected products. The flaw is classified as easily exploitable but requires the attacker to have existing logon access to the infrastructure where the MySQL instance is executing (Local attack vector). Despite the local requirement, the exploit does not require administrative privileges or user interaction. Successful exploitation results in a total loss of confidentiality, integrity, and availability. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats