Junglewise Threat Intelligence

CVE-2026-61128: Oracle MySQL Server denial of service in Optimizer

CVE-2026-61128 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: Oracle Mysql Cluster, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Optimizer component of Oracle MySQL Server and MySQL Cluster, which are widely used database management systems. A high-privileged attacker with network access can exploit this flaw to cause the database to hang or crash repeatedly. This results in a complete denial-of-service, preventing legitimate users and applications from accessing critical data.

Technical details

This vulnerability is located in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster. It is classified as a denial-of-service (DoS) flaw that can be triggered by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a frequently repeatable crash or a system hang, impacting the availability of the database. The issue affects versions 9.7.0 through 9.7.1 of both MySQL Server and MySQL Cluster. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle MySQL Server 9.7.0-9.7.1
  • Oracle MySQL Cluster 9.7.0-9.7.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats