Junglewise Threat Intelligence

CVE-2026-60184: Oracle MySQL Server and Cluster denial of service in Replication

CVE-2026-60184 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Replication component of Oracle MySQL Server and MySQL Cluster can allow an attacker to crash the database service. MySQL is a widely used database system for storing and managing corporate data; an exploit would result in a complete denial of service, making applications and data unavailable. Exploitation is considered difficult and requires the attacker to already possess high-level administrative privileges.

Technical details

This vulnerability affects the Server: Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial of service (DoS) flaw that allows a high-privileged attacker with network access via multiple protocols to cause a hang or a frequently repeatable crash. The attack complexity is rated as high, suggesting that successful exploitation may depend on specific configurations or timing conditions. The impact is limited to availability, with no reported impact on data confidentiality or integrity. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats