Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates in the DDL handling component of Oracle MySQL Server and MySQL Cluster. A high privileged attacker who can reach the database over the network using one or more supported protocols can exploit this weakness to cause the server or cluster to hang or to repeatedly crash. Successful exploitation results in a complete denial of service, affecting the availability of the database service but not compromising confidentiality or integrity. The flaw is rated with a CVSS 3.1 base score of 4.4, indicating moderate severity. The flaw is categorized as CWE-284 (Improper Access Control), indicating that an attacker could exploit authorization weaknesses to trigger the crash.

Affected Systems

Oracle Corporation MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 are vulnerable, as are Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. These products are offered by Oracle Corporation.

Risk and Exploitability

The CVSS score places the issue in the moderate range, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no widely known, actively used exploit in the marketplace. An attacker still requires high privileges on the database and network reachability, indicating that protection by network segmentation, firewall rules, and strict role-based access controls will mitigate the risk. If the security patch is not applied, the primary method of exploitation would likely involve sending specially crafted DDL statements over an authenticated session to trigger the crash. This is an authorization-related weakness (CWE-284), underscoring the need to enforce strict role-based controls.

Generated by OpenCVE AI on August 3, 2026 at 00:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle security patches or updates that address the vulnerability for the affected MySQL Server and MySQL Cluster versions.
  • Restrict network access to the MySQL instances to only trusted hosts and expose only the necessary ports, using firewalls or ACLs to block unwarranted traffic.
  • Monitor MySQL logs for unusual or repeated high-frequency DDL operations, and configure resource limits or automated restarts to contain potential denial‑of‑service incidents.
  • Verify that only authorized users have DDL permissions by implementing strict role‑based access controls, ensuring that privilege escalation is prevented.

Generated by OpenCVE AI on August 3, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title mysql: DDL unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-413
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via DDL in Oracle MySQL Server and Cluster
Weaknesses CWE-264

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via DDL in Oracle MySQL Server and Cluster
Weaknesses CWE-264

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:18:43.077Z

Reserved: 2026-05-18T15:55:10.312Z

Link: CVE-2026-46936

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:50.693Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-46936 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses