Executive brief
A vulnerability in the Optimizer component of Oracle MySQL Server and MySQL Cluster can allow an authorized user to crash the database service. This results in a complete denial-of-service, preventing applications and users from accessing stored data. While the attack requires high-level administrative privileges, it can be executed remotely over the network to disrupt business operations.
Technical details
A vulnerability exists in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster (versions 9.7.0 through 9.7.1). The flaw is easily exploitable by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to trigger a hang or a frequently repeatable crash, leading to a complete denial-of-service (DoS) of the affected database instance. The vulnerability is tracked as CVE-2026-61144 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle MySQL Server 9.7.0-9.7.1
- Oracle MySQL Cluster 9.7.0-9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date