Unauthenticated Network Vulnerability in Oracle MySQL Cluster
CVE-2026-70724

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70724?

A vulnerability in the Oracle MySQL Cluster product allows unauthenticated attackers with network access via HTTP to exploit the system. Exploiting this vulnerability requires human interaction from a user, who is not the attacker. If successful, the attacker can take control of the MySQL Cluster, resulting in significant impacts to confidentiality, integrity, and availability of data. Affected versions include MySQL Cluster 8.0.0 to 8.0.48, 8.4.0 to 8.4.11, and 9.7.0 to 9.7.2. Organizations using these versions should take immediate action to secure their systems.

Affected Version(s)

MySQL Cluster 8.0.0 <= 8.0.48

MySQL Cluster 8.4.0 <= 8.4.11

MySQL Cluster 9.7.0 <= 9.7.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.