Junglewise Threat Intelligence

CVE-2026-60190: Oracle MySQL Server denial of service in Replication component

CVE-2026-60190 · Severity: low · CVSS 2.2 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the replication component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A highly privileged attacker could exploit this flaw to cause a partial denial of service, potentially slowing down or disrupting database availability. While the impact is limited to availability, it could affect business operations that rely on consistent database performance.

Technical details

This vulnerability affects the Replication component of MySQL Server and MySQL Cluster. It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have high privileges (PR:H) and network access via multiple protocols. Successful exploitation allows an attacker to cause a partial denial of service (Availability impact). Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats