Vulnerability in MySQL Server and MySQL Cluster by Oracle
CVE-2026-60315

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60315?

A vulnerability has been identified in MySQL Server and MySQL Cluster by Oracle, specifically within the Server X Plugin component. This flaw allows an unauthenticated attacker with network access through various protocols to exploit the system, potentially leading to a denial of service (DoS) by causing the MySQL Server or Cluster to hang or crash frequently. Furthermore, successful exploitation can grant unauthorized read access to specific sets of data available within the affected MySQL products, posing significant risks to confidentiality and availability of data.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.