Vulnerability in MySQL Server and MySQL Cluster by Oracle
CVE-2026-60186

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60186?

MySQL Server and MySQL Cluster from Oracle are susceptible to a denial-of-service vulnerability within the Group Replication Plugin. This flaw can be exploited by an attacker with elevated privileges and network access using various protocols. If successfully exploited, this vulnerability may lead to the malicious actor causing the MySQL Server or MySQL Cluster to hang or crash repeatedly, thereby impacting availability. Systems running supported versions between 8.4.0 to 8.4.10 for MySQL Server and MySQL Cluster, as well as 9.7.0 to 9.7.1, are particularly at risk.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.