MySQL Server Vulnerability in Oracle Product
CVE-2026-60191

4.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60191?

A vulnerability within Oracle's MySQL Server and MySQL Cluster products allows a high-privileged attacker, who has logon access to the system, to exploit the affected versions. The exploit is characterized by the ability to cause frequent crashes or a denial of service condition in MySQL Server and MySQL Cluster instances. This exposure requires an attacker to have local access to the infrastructure, making it crucial for organizations to ensure robust access controls to protect their database environments.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.