Impact
The vulnerability is in the Group Replication Plugin of Oracle MySQL Server and MySQL Cluster; it allows an unauthenticated local attacker who can log onto the infrastructure where the database runs to exploit improper access control (CWE-284) and privilege escalation (CWE-266), achieving a full takeover and resulting in complete loss of confidentiality, integrity, and availability.
Affected Systems
Affected are Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1.
Risk and Exploitability
The CVSS base score of 8.4 indicates high severity with confidentiality, integrity and availability impacts, while the EPSS score of less than 1% suggests the vulnerability is rarely exploited today and it is not listed in the CISA KEV catalog. Nevertheless, because the attack vector is local, any user who can log into the database host—without authentication to MySQL itself—can run the exploit and gain full control of the server or cluster, leveraging improper access control (CWE-284) and privilege escalation (CWE-266). The risk is therefore contingent on the availability of local accounts; environments that restrict local access to privileged users mitigate the threat, but broader local access still poses a significant risk.
OpenCVE Enrichment