Executive brief
A vulnerability exists in the Oracle MySQL Connector/C++ library, which is used by applications to communicate with MySQL databases. An attacker could exploit this flaw to gain unauthorized access to sensitive data or modify critical information stored in the database. While the attack is difficult to execute, it could lead to a significant breach of data confidentiality and integrity for affected applications.
Technical details
This vulnerability affects the Connector/C++ component of Oracle MySQL Connectors. It is characterized by a high attack complexity, meaning successful exploitation relies on specific conditions beyond the attacker's direct control. An unauthenticated attacker can exploit this over a network using multiple protocols to gain unauthorized read, create, delete, or modification access to data accessible via the connector. The vulnerability primarily impacts confidentiality and integrity, with no reported impact on system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle MySQL Connectors (Connector/C++) 9.7.0 - 9.7.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory