Executive brief
A vulnerability in the MySQL Cluster NDB Operator could allow an unauthorized person with access to the underlying server infrastructure to view sensitive database information. While the flaw is difficult to exploit, a successful attack could lead to the exposure of critical business data or a complete breach of all data stored within the cluster. This affects organizations using specific versions of Oracle's high-availability database clustering solution.
Technical details
This vulnerability exists in the NDB Operator component of Oracle MySQL Cluster. It is classified as a local attack (AV:L) with high complexity (AC:H), requiring the attacker to have existing logon access to the infrastructure where the cluster executes. Although no specific privileges are required (PR:N) and no user interaction is needed (UI:N), the exploit allows for unauthorized access to critical data, impacting confidentiality (C:H). The vulnerability affects versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation guidance.
Affected products
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD