Junglewise Threat Intelligence

CVE-2026-60586: Oracle MySQL Connector/J unauthorized data access

CVE-2026-60586 · Severity: high · CVSS 7.7 · Published 2026-07-21

Technologies: Oracle Connector/J. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle MySQL Connector/J, a software component that allows Java applications to communicate with MySQL databases. An attacker with low-level access to the network could exploit this flaw to gain unauthorized access to sensitive data. This could lead to a significant breach of confidential information across the affected systems and potentially impact other integrated products.

Technical details

This vulnerability affects the Connector/J component of Oracle MySQL Connectors. It is classified as easily exploitable, requiring only low privileges and network access via multiple protocols. The exploit results in a scope change (S:C), meaning the impact can extend beyond the MySQL Connector itself to other products or the underlying environment. The primary impact is a high loss of confidentiality (C:H), potentially allowing an attacker to access all data reachable by the connector. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle MySQL Connectors (Connector/J) 9.7.0 - 9.7.1

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update
  • 2026-07-21: disclosed

References

Related threats