Junglewise Threat Intelligence

CVE-2026-60189: Oracle MySQL Server and Cluster denial of service in Replication component

CVE-2026-60189 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the replication component of Oracle MySQL Server and MySQL Cluster could allow an attacker to disrupt database services. If exploited, the database may hang or crash repeatedly, leading to a complete denial of service for applications that rely on it. This issue requires high-level administrative privileges to exploit and is considered difficult to execute.

Technical details

A vulnerability exists in the Server: Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial of service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. The exploit is characterized as having high complexity (AC:H), meaning specific conditions must be met for a successful attack. If successful, the attacker can cause the MySQL instance to hang or crash repeatedly. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60189 by Oracle

References

Related threats