Junglewise Threat Intelligence

CVE-2026-60188: Oracle MySQL denial of service in Server Replication

CVE-2026-60188 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the replication component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A highly privileged attacker could exploit this flaw to cause the database to hang or crash repeatedly. This would result in a complete denial of service, preventing applications and users from accessing critical data.

Technical details

This vulnerability is located in the Server: Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial of service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. The attack is considered difficult to exploit (Attack Complexity: High) but can result in a frequently repeatable crash or a complete hang of the affected database instance. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users are advised to consult the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle MySQL Server业务 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle

References

Related threats