Junglewise Threat Intelligence

CVE-2026-60331: Oracle MySQL Server and MySQL Cluster takeover in Replication component

CVE-2026-60331 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Replication component of Oracle MySQL Server and MySQL Cluster could allow a highly privileged user with local access to the underlying infrastructure to take full control of the database system. MySQL is a widely used database management system for storing and managing critical business data. While the attack is difficult to execute and requires significant existing access, a successful exploit could lead to a total loss of data confidentiality, integrity, and service availability.

Technical details

This vulnerability exists in the Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have high-level privileges and local logon access to the infrastructure where the MySQL instance is running. If successfully exploited, the attacker can achieve a complete takeover of the MySQL Server or Cluster, impacting confidentiality, integrity, and availability. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.

References

Related threats