Junglewise Threat Intelligence

CVE-2026-60181: Oracle MySQL Server and MySQL Cluster takeover in Configurator

CVE-2026-60181 · Severity: medium · CVSS 6.7 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Configurator component of Oracle MySQL Server and MySQL Cluster could allow a local user to take full control of the database system. To succeed, an attacker must already have access to the underlying server infrastructure and trick another user into performing a specific action. If exploited, this could lead to the complete loss of data confidentiality, integrity, and service availability.

Technical details

A vulnerability in the Server: Configurator component of Oracle MySQL Server and MySQL Cluster (versions 9.7.0-9.7.1) allows a low-privileged attacker with local infrastructure access to compromise the database. The exploit is characterized by high complexity (AC:H) and requires interaction from a person other than the attacker (UI:R). Successful exploitation can result in a complete takeover of the MySQL Server or Cluster instance, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60181 and was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats