Executive brief
A vulnerability exists in Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. An attacker with existing access to the underlying server infrastructure could potentially modify, insert, or delete certain data within the database. While the impact is limited to data integrity and the attack is difficult to perform, it could lead to unauthorized changes in business records.
Technical details
This vulnerability affects the 'Server: Pluggable Auth' component of Oracle MySQL Server and MySQL Cluster. It is classified as a local attack (AV:L) with high complexity (AC:H), meaning an attacker must already have logon access to the infrastructure where the MySQL instance is running. If successfully exploited, the attacker can achieve unauthorized update, insert, or delete access to a subset of the data accessible by the server. The vulnerability does not impact data confidentiality or service availability. Affected versions include MySQL Server 8.4.x and 9.7.x, and MySQL Cluster 8.0.x, 8.4.x, and 9.7.x.
Affected products
- Oracle MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1
- Oracle MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update advisory.
- 2026-07-21: disclosed