Executive brief
A vulnerability exists in the Oracle MySQL Connector/Net, a software component used by applications to communicate with MySQL databases. An attacker could exploit this to gain unauthorized access to sensitive information or modify critical data within the application's environment. While the attack is difficult to execute, a successful breach could compromise the integrity and confidentiality of all data accessible by the connector.
Technical details
This vulnerability affects the Connector/Net component of Oracle MySQL Connectors. It is classified as a high-complexity network attack that does not require user interaction or prior authentication. Successful exploitation allows an attacker to gain unauthorized 'read' and 'write' access to critical data or all data accessible via the MySQL Connector. The attack vector involves multiple protocols, though specific technical root causes (such as specific API calls or memory management issues) were not disclosed in the Oracle advisory. The vulnerability has been addressed in the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle MySQL Connectors (Connector/Net) 9.7.0 - 9.7.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed