Junglewise Threat Intelligence

CVE-2026-60174: Oracle MySQL Optimizer denial of service

CVE-2026-60174 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. An attacker with basic user permissions can remotely trigger a system hang or a repeated crash, leading to a complete denial of service. This could disrupt business operations by making critical data and applications unavailable to users.

Technical details

This vulnerability is located in the Server: Optimizer component of Oracle MySQL. It is classified as a denial of service (DoS) flaw that can be triggered by a low-privileged attacker with network access via multiple protocols. The root cause allows an unauthorized user to cause a hang or a frequently repeatable crash of the MySQL Server or MySQL Cluster instance. The vulnerability affects versions 9.7.0 and 9.7.1. Exploitation does not require user interaction or high privileges, but does require a valid (low-level) authenticated session.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats