Executive brief
A vulnerability in the Clone Plugin component of Oracle MySQL Server and MySQL Cluster could allow a highly privileged user to take full control of the database system. While the attack requires significant administrative access and is considered difficult to execute, a successful exploit would compromise the confidentiality, integrity, and availability of all data stored within the database. This could lead to unauthorized data access, data modification, or a complete service outage.
Technical details
This vulnerability exists in the Server: Clone Plugin component of Oracle MySQL Server and MySQL Cluster. It is classified as a high-complexity attack requiring high privileges (PR:H) and network access via multiple protocols. An attacker with these elevated permissions can exploit the flaw to achieve a complete takeover of the MySQL Server or Cluster instance, impacting confidentiality, integrity, and availability. The vulnerability affects MySQL Server versions 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster versions 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date