Junglewise Threat Intelligence

CVE-2026-60192: Oracle MySQL Connector/Net remote compromise

CVE-2026-60192 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Connector/Net. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle MySQL Connector/Net, a software component used by applications to communicate with MySQL databases. If exploited, an attacker could gain full control over the connector, potentially leading to the theft of sensitive data, unauthorized modification of information, or disruption of database services. While the attack is difficult to execute, it can be performed remotely without needing any user credentials.

Technical details

A vulnerability in the Connector/Net component of Oracle MySQL Connectors (versions 9.7.0 through 9.7.1) allows an unauthenticated attacker with network access via multiple protocols to compromise the system. The vulnerability is classified as difficult to exploit (Attack Complexity: High), but a successful attack results in a complete loss of confidentiality, integrity, and availability (Base Score 8.1). The flaw allows for a total takeover of the MySQL Connectors component. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle MySQL Connectors (Connector/Net) 9.7.0 - 9.7.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats