Impact
This vulnerability in the MySQL NDB Cluster component known as Cluster: NDB Operator permits an attacker who already has network access via HTTP to create, delete, or modify data stored in the cluster, thereby compromising both confidentiality and integrity of all data accessible through the cluster. The flaw does not impact availability, but the ability to tamper with critical data represents a severe breach.
Affected Systems
Oracle Corporation’s MySQL NDB Cluster versions 8.0.11 through 8.0.46, 8.4.0 through 8.4.9, and 9.0.0 through 9.7.0 are affected. Any deployment of these releases that exposes the Cluster: NDB Operator endpoint over HTTP remains vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, yet the availability of a low-privileged credential and network access means that an attacker could leverage it from a remote location. The reliance on HTTP communication and the lack of strict authorization controls make the attack vector straightforward, provided the network conditions allow the attacker to reach the vulnerable service.
OpenCVE Enrichment