Junglewise Threat Intelligence

CVE-2026-60585: Oracle MySQL Server and MySQL Cluster compromise in Replication component

CVE-2026-60585 · Severity: medium · CVSS 6.6 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the replication component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. If exploited, a highly privileged attacker could take complete control of the database server, potentially leading to the theft of sensitive data, unauthorized modification of records, or service outages. While the impact is severe, the attack is considered difficult to execute and requires the attacker to already possess high-level administrative credentials.

Technical details

This vulnerability affects the Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as a high-complexity attack (AC:H) that requires high-privileged credentials (PR:H) to execute. An attacker with network access via multiple protocols can exploit this flaw to compromise the server, leading to a full loss of confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability is present in MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation guidance.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats