Junglewise Threat Intelligence

CVE-2026-60747: Oracle MySQL Server and MySQL Cluster denial of service in Replication

CVE-2026-60747 · Severity: medium · CVSS 6.2 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the replication component of Oracle MySQL Server and MySQL Cluster could allow an attacker with access to the underlying system to disrupt database services. Successful exploitation can lead to a complete denial of service by causing the database to hang or crash repeatedly. This impact prevents legitimate users and applications from accessing critical data, potentially halting business operations.

Technical details

A vulnerability in the Server: Replication component of Oracle MySQL Server and MySQL Cluster allows for a denial of service (DoS). The flaw is categorized as easily exploitable and requires the attacker to have local logon access to the infrastructure where the MySQL instance is running. While the attacker does not need prior authentication within the MySQL application itself, they must be able to interact with the local environment. Successful exploitation results in a complete loss of availability by causing a hang or a frequently repeatable crash of the MySQL service. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60747

References

Related threats