Junglewise Threat Intelligence

CVE-2026-60183: Oracle MySQL Server and Cluster compromise in Clone Plugin

CVE-2026-60183 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the MySQL Server and MySQL Cluster Clone Plugin could allow a highly privileged user with local access to the underlying system to fully compromise the database. If successfully exploited, an attacker could take complete control of the database server, potentially leading to the theft of sensitive data or disruption of services. This issue is considered difficult to exploit and requires existing high-level access to the server infrastructure.

Technical details

A vulnerability exists in the Clone Plugin component of Oracle MySQL Server and MySQL Cluster. The flaw allows a high-privileged attacker with local logon access to the host infrastructure to compromise the MySQL instance. The attack vector is local (AV:L) and requires high privileges (PR:H), with a high level of complexity (AC:H) to successfully execute. A successful exploit results in a complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H), effectively allowing a full takeover of the MySQL Server or Cluster. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats