Junglewise Threat Intelligence

CVE-2026-60315: Oracle MySQL Server and Cluster denial of service in X Plugin

CVE-2026-60315 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the MySQL database server's X Plugin component allows an attacker to remotely crash the database or access sensitive information. This could lead to a total service outage for applications relying on the database and unauthorized viewing of customer or business data. The issue is easily exploitable over the network without requiring any login credentials.

Technical details

A vulnerability exists in the X Plugin component of Oracle MySQL Server and MySQL Cluster. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the server. Successful exploitation can lead to a complete denial-of-service (DoS) by causing the server to hang or crash repeatedly. Additionally, the attacker can gain unauthorized read access to a subset of the data stored in the database. The vulnerability affects MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats