Executive brief
A vulnerability in the Configurator component of Oracle MySQL Server and MySQL Cluster could allow a local user to take full control of the database system. To succeed, an attacker must already have access to the underlying server infrastructure and trick another user into performing a specific action. If exploited, this could lead to the complete loss of data confidentiality, integrity, and service availability.
Technical details
A vulnerability in the Server: Configurator component of Oracle MySQL Server and MySQL Cluster (versions 9.7.0-9.7.1) allows a low-privileged attacker with local infrastructure access to compromise the database. The exploit is characterized by high complexity (AC:H) and requires interaction from a person other than the attacker (UI:R). Successful exploitation can result in a complete takeover of the MySQL Server or Cluster instance, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60181 and was disclosed as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle MySQL Server 9.7.0-9.7.1
- Oracle MySQL Cluster 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date