Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Group Replication Plugin of Oracle MySQL Server and MySQL Cluster; it allows an unauthenticated local attacker who can log onto the infrastructure where the database runs to exploit improper access control (CWE-284) and privilege escalation (CWE-266), achieving a full takeover and resulting in complete loss of confidentiality, integrity, and availability.

Affected Systems

Affected are Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1.

Risk and Exploitability

The CVSS base score of 8.4 indicates high severity with confidentiality, integrity and availability impacts, while the EPSS score of less than 1% suggests the vulnerability is rarely exploited today and it is not listed in the CISA KEV catalog. Nevertheless, because the attack vector is local, any user who can log into the database host—without authentication to MySQL itself—can run the exploit and gain full control of the server or cluster, leveraging improper access control (CWE-284) and privilege escalation (CWE-266). The risk is therefore contingent on the availability of local accounts; environments that restrict local access to privileged users mitigate the threat, but broader local access still poses a significant risk.

Generated by OpenCVE AI on August 2, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle MySQL Server or MySQL Cluster patch or upgrade to a version beyond the affected ranges (e.g., 8.4.11 or newer, 9.7.2 or newer).
  • If your deployment does not require the Group Replication Plugin, disable or remove it to eliminate the attack surface.
  • Restrict local user access to the database host, enforce least privilege, and monitor for suspicious local activity.

Generated by OpenCVE AI on August 2, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Privilege Escalation Allowing Full Takeover of MySQL Server/Cluster mysql: Group Replication Plugin unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Important


Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Privilege Escalation Allowing Full Takeover of MySQL Server/Cluster

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:08.986Z

Reserved: 2026-07-08T15:51:40.516Z

Link: CVE-2026-60163

cve-icon Vulnrichment

Updated: 2026-07-23T15:11:58.473Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60163 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control