Junglewise Threat Intelligence

CVE-2026-60177: Oracle MySQL Server and Cluster denial of service in Clone Plugin

CVE-2026-60177 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Clone Plugin component of Oracle MySQL Server and MySQL Cluster could allow an attacker to crash the database service. While the attack is difficult to execute and requires high-level administrative privileges, a successful exploit results in a complete denial of service, making the database unavailable for legitimate operations. This could disrupt business applications and services that rely on these databases for data storage and retrieval.

Technical details

A vulnerability in the Server: Clone Plugin component of Oracle MySQL Server and MySQL Cluster allows a high-privileged attacker with network access via multiple protocols to cause a denial of service. The exploit is characterized as difficult to perform (Attack Complexity: High) and requires administrative-level permissions (Privileges Required: High). Successful exploitation results in a frequently repeatable crash or a complete hang of the MySQL Server or Cluster instance. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats