Junglewise Threat Intelligence

CVE-2026-60316: Oracle MySQL Server and Cluster compromise in X Plugin

CVE-2026-60316 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the MySQL Server and MySQL Cluster X Plugin component could allow a high-privileged user to take full control of the database system. MySQL is a widely used database management system for storing and retrieving corporate data. A successful exploit could lead to a complete loss of data confidentiality, integrity, and service availability, potentially impacting business operations and sensitive information.

Technical details

A vulnerability exists in the X Plugin component of Oracle MySQL Server and MySQL Cluster. The flaw allows a high-privileged attacker with network access via multiple protocols to compromise the server. While the specific technical root cause is not detailed in the advisory, the exploit is described as 'easily exploitable' and results in a complete takeover of the affected MySQL instance. This impacts confidentiality, integrity, and availability (CVSS 7.2). Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial publication of the CVE record
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats