Executive brief
A vulnerability in the MySQL database server and cluster software can allow a user with basic login credentials to crash the database service. This component is responsible for managing and retrieving data for applications; an exploit would result in a complete service outage, preventing applications from accessing their data. This impacts business operations by causing downtime and requiring manual intervention to restore database availability.
Technical details
A denial of service (DoS) vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster. The flaw is easily exploitable by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to trigger a hang or a frequently repeatable crash, resulting in a complete loss of availability for the affected database instance. The vulnerability affects versions 9.0.0 through 9.7.1 of both MySQL Server and MySQL Cluster. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle MySQL Server 9.0.0-9.7.1
- Oracle MySQL Cluster 9.0.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date