MySQL Server and MySQL Cluster Vulnerability in Oracle MySQL
CVE-2026-60316

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60316?

An improper authentication vulnerability in Oracle MySQL affects multiple versions of MySQL Server and MySQL Cluster. A highly privileged attacker with network access can exploit this flaw through various protocols, allowing unauthorized access and potential takeover of the MySQL environments. This issue impacts the confidentiality, integrity, and availability of the database systems, posing significant security risks to applications relying on MySQL.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.