Junglewise Threat Intelligence

CVE-2026-61082: Oracle MySQL Connector/J unauthorized data access

CVE-2026-61082 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Connector/J. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's MySQL Connector/J, a software component used by Java applications to communicate with MySQL databases. An attacker could exploit this flaw to gain unauthorized access to sensitive data managed by the connector. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a link or interacting with a malicious site, while the application is running.

Technical details

A vulnerability in the Connector/J component of Oracle MySQL Connectors (versions 9.7.0-9.7.1) allows an unauthenticated attacker with network access via multiple protocols to compromise the library. The vulnerability is classified with a confidentiality impact, meaning it can lead to unauthorized access to critical data or complete access to all data accessible by the connector. The attack vector is network-based and requires user interaction (UI:R), suggesting a scenario where a user must be tricked into performing an action that triggers the flaw. The CVSS 3.1 base score is 6.5, reflecting high confidentiality impact but no impact on integrity or availability.

Affected products

  • Oracle MySQL Connectors (Connector/J) 9.7.0 through 9.7.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update.
  • 2026-07-21: advisory: NVD published the CVE record.

References

Related threats