Junglewise Threat Intelligence

CVE-2026-60195: Oracle MySQL Server denial of service in JSON Duality

CVE-2026-60195 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle MySQL Server and MySQL Cluster within the JSON Duality component. An attacker with high-level administrative privileges can remotely trigger a system hang or a repeated crash. This results in a complete denial of service, making the database unavailable for legitimate business operations and applications.

Technical details

This vulnerability affects the Server: JSON Duality component of Oracle MySQL Server and MySQL Cluster versions 9.7.0 through 9.7.1. It is classified as a denial of service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the server instance. The attack is considered easily exploitable (low attack complexity) but requires high administrative privileges (PR:H). The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats