Junglewise Threat Intelligence

CVE-2026-60191: Oracle MySQL Server and Cluster denial of service in Replication

CVE-2026-60191 · Severity: medium · CVSS 4.1 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the replication component of Oracle MySQL Server and MySQL Cluster could allow a highly privileged user to crash the database service. While difficult to exploit, a successful attack results in a complete denial of service, causing the database to hang or repeatedly crash. This impacts the availability of applications and services that rely on these databases for data storage and retrieval.

Technical details

A vulnerability exists in the Replication component of Oracle MySQL Server and MySQL Cluster. The flaw is characterized by a high complexity of exploitation and requires the attacker to have high privileges and local access to the underlying infrastructure where the database is running. If successfully exploited, the attacker can cause a hang or a frequently repeatable crash of the MySQL instance, leading to a complete denial of service. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.

References

Related threats