Junglewise Threat Intelligence

CVE-2026-60725: Oracle MySQL Router data compromise in Router General component

CVE-2026-60725 · Severity: high · CVSS 7.4 · Published 2026-07-21

Technologies: Oracle MySQL Router. Vendors: Oracle.

Executive brief

A security vulnerability has been identified in Oracle MySQL Router, a tool used to manage high availability and routing for MySQL databases. An unauthenticated attacker could exploit this flaw over a network to gain unauthorized access to sensitive database information or modify critical data. While the attack is considered difficult to execute, a successful exploit could lead to a complete compromise of the data managed by the router, potentially impacting business operations and data integrity.

Technical details

This vulnerability exists in the 'Router: General' component of Oracle MySQL Router. It is classified as a network-based attack reachable via HTTP that does not require user interaction or prior authentication. The attack complexity is rated as high, suggesting that successful exploitation may depend on specific environmental conditions or timing. If exploited, the attacker can achieve high confidentiality and integrity impacts, allowing for the unauthorized viewing or alteration of all data managed by the MySQL Router instance. Affected versions include 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1.

Affected products

  • Oracle MySQL Router 8.4.0 - 8.4.10, 9.7.0 - 9.7.1

Timeline

  • 2026-07-21: disclosed: Initial publication by Oracle and NVD
  • 2026-07-21: advisory

References

Related threats