Executive brief
Oracle MySQL Connector/Net, a software component used by applications to communicate with MySQL databases, contains a vulnerability that could allow an attacker to take full control of the connector. While the flaw is difficult to exploit, a successful attack by a user with low-level network access could potentially impact other connected systems and data. This could lead to unauthorized access to sensitive information or disruption of database-dependent business operations.
Technical details
This vulnerability affects the Connector/Net component of Oracle MySQL Connectors. It is classified as difficult to exploit (High Attack Complexity) but allows a low-privileged attacker with network access via multiple protocols to compromise the system. The vulnerability is notable for a scope change (Status: C), meaning a successful exploit can impact components beyond the immediate security scope of the MySQL Connector itself, potentially leading to a full takeover. The CVSS 3.1 base score is 8.5, reflecting high impacts on confidentiality, integrity, and availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle MySQL Connectors (Connector/Net) 9.7.0 - 9.7.1
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD