Junglewise Threat Intelligence

CVE-2026-70724: Oracle MySQL Cluster remote code execution

CVE-2026-70724 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Mysql Cluster. Vendors: Oracle.

Executive brief

MySQL Cluster is Oracle's distributed database product used for high-availability applications requiring real-time data access. An unauthenticated attacker with network access can exploit a vulnerability in the cluster management interface to gain complete control over the database system, compromising confidentiality, integrity, and availability of all stored data. The attack requires user interaction and is difficult to execute, but successful exploitation leads to full system compromise.

Technical details

A vulnerability in MySQL Cluster's general component allows an unauthenticated attacker to compromise the system via HTTP with network access. The vulnerability requires human interaction from a person other than the attacker and is difficult to exploit (CVSS AC:H), indicating non-trivial preconditions or social engineering requirements. Successful exploitation results in complete takeover of the MySQL Cluster, affecting confidentiality, integrity, and availability. The vulnerability impacts versions 8.0.0–8.0.48, 8.4.0–8.4.11, and 9.7.0–9.7.2; patch availability details are not provided in the advisory.

Affected products

  • Oracle MySQL Cluster 8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2

Timeline

  • 2026-08-18: disclosed

References

Related threats