Junglewise Threat Intelligence

CVE-2026-61094: Oracle MySQL Server and MySQL Cluster compromise in Replication component

CVE-2026-61094 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the replication component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A high-privileged attacker could exploit this flaw to gain full control over the database server. This could lead to the unauthorized access, modification, or deletion of sensitive business data and cause significant service disruptions.

Technical details

This vulnerability affects the Replication component of Oracle MySQL Server and MySQL Cluster. It is classified as an easily exploitable flaw that allows a high-privileged attacker (PR:H) with network access via multiple protocols (AV:N) to compromise the server without user interaction (UI:N). Successful exploitation can result in a complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H), effectively allowing a full system takeover. The issue impacts MySQL Server versions 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster versions 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
  • Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats