Denial of Service Vulnerability in MySQL Server and MySQL Cluster by Oracle
CVE-2026-60187

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60187?

A vulnerability present in Oracle’s MySQL Server and MySQL Cluster products allows a high-privileged attacker with network access to disrupt service. The exploitation of this flaw can lead to the server experiencing hang-ups or frequent crashes, resulting in a Denial of Service (DoS) condition. Supported versions affected include multiple iterations of MySQL Server and Cluster, highlighting the critical need for patching to avoid service interruptions.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.