Junglewise Threat Intelligence

CVE-2026-60182: Oracle MySQL Server and Cluster denial of service in Clone Plugin

CVE-2026-60182 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Clone Plugin component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A highly privileged attacker could exploit this flaw to cause the database to hang or crash repeatedly. This would result in a complete denial of service, making the database and any dependent applications unavailable to users.

Technical details

A vulnerability in the Server: Clone Plugin component of Oracle MySQL Server and MySQL Cluster allows for a denial of service (DoS). The flaw is reachable via multiple protocols over a network, though it requires high privileges and is considered difficult to exploit (High Attack Complexity). Successful exploitation allows an attacker to cause a hang or a frequently repeatable crash of the MySQL instance. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats