Vulnerability in MySQL Cluster Affects Oracle MySQL
CVE-2026-60592

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60592?

A vulnerability has been identified in the Cluster component of Oracle MySQL that permits unauthenticated attackers with network access to exploit multiple protocols. This can lead to a complete denial of service, causing MySQL Cluster instances to hang or crash repeatedly. Additionally, the vulnerability provides attackers with unauthorized access to perform update, insert, or delete operations on certain data within the MySQL Cluster. The affected versions span 8.0.0 to 8.0.47, 8.4.0 to 8.4.10, and 9.7.0 to 9.7.1.

Affected Version(s)

MySQL Cluster 8.0.0 <= 8.0.47

MySQL Cluster 8.4.0 <= 8.4.10

MySQL Cluster 9.7.0 <= 9.7.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.