Junglewise Threat Intelligence

CVE-2026-60623: Oracle MySQL Connector/J unauthorized data access and modification

CVE-2026-60623 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Connector/J. Vendors: Oracle.

Executive brief

Oracle MySQL Connector/J, a software component that allows Java applications to communicate with MySQL databases, contains a security vulnerability. An attacker with low-level access to the network could potentially view, modify, or delete sensitive data managed by the connector. Additionally, this flaw could be used to cause a partial service disruption, impacting the reliability of applications that rely on this database connection.

Technical details

A vulnerability in the Connector/J component of Oracle MySQL Connectors allows a low-privileged attacker with network access via multiple protocols to compromise the system. The vulnerability is classified as difficult to exploit (Attack Complexity: High). Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible via the connector. It also allows for a partial denial of service (DoS). The issue affects supported versions 9.7.0 through 9.7.1 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle MySQL Connectors (Connector/J) 9.7.0 - 9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats