Vulnerability in MySQL Server and Cluster by Oracle
CVE-2026-60332

6.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60332?

This vulnerability in Oracle's MySQL Server and MySQL Cluster components could allow an attacker with high privileges to exploit the Group Replication GCS feature. When successfully exploited, this could lead to a compromise of the database environment, resulting in complete control over the MySQL Server and MySQL Cluster instances. The affected versions may allow unauthorized access if proper security measures are not implemented, emphasizing the need for vigilant security practices.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.