Authentication Bypass Vulnerability in MySQL Server and Cluster by Oracle
CVE-2026-61096

2.9LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61096?

An authentication bypass vulnerability exists in the Oracle MySQL Server and MySQL Cluster products. This flaw affects several versions and allows an unauthenticated attacker with access to the underlying infrastructure to compromise the security of the MySQL Server and Cluster. Successful exploitation can result in unauthorized alterations to data, including updates, inserts, or deletions, affecting the integrity of the stored information. Organizations utilizing the affected versions should apply mitigations or updates to secure their systems.

Affected Version(s)

MySQL Cluster 8.0.0-8.0.47

MySQL Cluster 8.4.0-8.4.10

MySQL Cluster 9.7.0-9.7.1

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.