Description
Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL NDB Cluster. While the vulnerability is in MySQL NDB Cluster, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL NDB Cluster accessible data as well as unauthorized access to critical data or complete access to all MySQL NDB Cluster accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-06-16
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in the MySQL NDB Cluster component known as Cluster: NDB Operator permits an attacker who already has network access via HTTP to create, delete, or modify data stored in the cluster, thereby compromising both confidentiality and integrity of all data accessible through the cluster. The flaw does not impact availability, but the ability to tamper with critical data represents a severe breach.

Affected Systems

Oracle Corporation’s MySQL NDB Cluster versions 8.0.11 through 8.0.46, 8.4.0 through 8.4.9, and 9.0.0 through 9.7.0 are affected. Any deployment of these releases that exposes the Cluster: NDB Operator endpoint over HTTP remains vulnerable.

Risk and Exploitability

The CVSS score of 9.6 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, yet the availability of a low-privileged credential and network access means that an attacker could leverage it from a remote location. The reliance on HTTP communication and the lack of strict authorization controls make the attack vector straightforward, provided the network conditions allow the attacker to reach the vulnerable service.

Generated by OpenCVE AI on June 17, 2026 at 20:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle MySQL NDB Cluster patch that removes the vulnerable NDB Operator endpoint or applies a fixed version beyond the affected ranges
  • Restrict network access to the Cluster: NDB Operator HTTP interface by configuring firewall rules or VPN isolation to only allow trusted administrative hosts
  • Disable or harden authentication for the HTTP API by enforcing strong credentials and, where possible, deploying TLS to protect data in transit

Generated by OpenCVE AI on June 17, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL NDB Cluster. While the vulnerability is in MySQL NDB Cluster, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL NDB Cluster accessible data as well as unauthorized access to critical data or complete access to all MySQL NDB Cluster accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle mysql Ndb Cluster
CPEs cpe:2.3:a:oracle:mysql_ndb_cluster:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Ndb Cluster
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Mysql Ndb Cluster
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:48:23.052Z

Reserved: 2026-05-18T15:55:10.307Z

Link: CVE-2026-46861

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:00:05Z

Weaknesses

No weakness.