Junglewise Threat Intelligence

CVE-2026-60171: Oracle MySQL Cluster denial of service in Server Optimizer

CVE-2026-60171 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster. Vendors: Oracle.

Executive brief

A vulnerability exists in the Optimizer component of Oracle MySQL Cluster, a high-availability database solution. A highly privileged attacker can exploit this flaw over a network to cause the database service to hang or crash repeatedly. This results in a complete denial of service, impacting the availability of applications and business operations relying on the database.

Technical details

This vulnerability is located in the Server: Optimizer component of Oracle MySQL Cluster. It is classified as an availability issue that allows a high-privileged attacker with network access via multiple protocols to compromise the system. Successful exploitation results in a complete denial of service (DoS) by causing the MySQL Cluster to hang or crash frequently. The vulnerability affects versions 8.0.0 through 8.0.47. No user interaction is required for exploitation, though the attacker must possess high-level privileges.

Affected products

  • Oracle MySQL Cluster 8.0.0 through 8.0.47

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats