Executive brief
A vulnerability in the Group Replication component of Oracle MySQL Server and MySQL Cluster could allow a highly privileged user with local access to the underlying system to take full control of the database. While the attack is difficult to execute and requires existing high-level access to the server infrastructure, a successful exploit could lead to a complete compromise of data confidentiality, integrity, and service availability. This could result in unauthorized data access or a total shutdown of database operations.
Technical details
This vulnerability exists in the Group Replication GCS component of Oracle MySQL Server and MySQL Cluster. It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have high-level privileges and local logon access to the infrastructure where the MySQL instance is running. If successfully exploited, the attacker can achieve a complete takeover of the MySQL Server or Cluster, impacting confidentiality, integrity, and availability. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date