Unauthenticated Access Vulnerability in Oracle MySQL Router
CVE-2026-60725

7.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60725?

A vulnerability exists in Oracle MySQL Router that allows an unauthenticated attacker with network access via HTTP to compromise the application. This flaw affects supported versions between 8.4.0 and 8.4.10 and 9.7.0 to 9.7.1. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, compromising both confidentiality and integrity. Attackers gain potential access to all MySQL Router accessible data, posing significant risks to data security and integrity.

Affected Version(s)

MySQL Router 8.4.0 <= 8.4.10

MySQL Router 9.7.0 <= 9.7.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.