Junglewise Threat Intelligence

CVE-2026-61093: Oracle MySQL Server denial of service in Optimizer

CVE-2026-61093 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. An attacker with basic user credentials can remotely trigger a system hang or a repeated crash, leading to a total loss of database availability. This could disrupt business operations and prevent applications from accessing critical data.

Technical details

A denial-of-service vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster versions 9.7.0 through 9.7.1. The flaw is categorized as easily exploitable, requiring only low-privileged user credentials and network access via multiple protocols. Successful exploitation allows an attacker to cause a hang or a frequently repeatable crash of the database service. The vulnerability is tracked as CVE-2026-61093 and was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61093 by Oracle.
  • 2026-07-21: advisory: Included in Oracle Critical Patch Update (CPU) July 2026.

References

Related threats