Executive brief
Oracle MySQL Server and MySQL Cluster are affected by a security vulnerability in the Performance Schema component, which is used for monitoring server execution. A highly privileged user, such as a database administrator, could exploit this flaw to gain unauthorized read access to a limited subset of data. While the risk to data confidentiality is low, it represents a breakdown in intended access controls for sensitive monitoring information.
Technical details
A vulnerability exists in the Performance Schema component of Oracle MySQL Server and MySQL Cluster. The flaw allows a high-privileged attacker (PR:H) with network access via multiple protocols to bypass certain read restrictions. Successful exploitation results in unauthorized read access to a subset of data accessible to the MySQL Server or Cluster. The vulnerability is considered easily exploitable (AC:L) but requires significant existing privileges. Affected versions include MySQL Server 8.4.0-8.4.10 and 9.7.0-9.7.1, and MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 CPU advisory.
- 2026-07-21: disclosed: CVE-2026-61081 was published to the NVD.