Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies within the Optimizer component of Oracle MySQL Server and MySQL Cluster. An attacker with low privileges and network access can exploit it to force the server or cluster to hang or crash, effectively denying availability to legitimate users. This flaw does not compromise confidentiality or integrity, but it allows an adversary to disrupt database services by repeatedly triggering a crash. The weakness can be classified as a resource exhaustion or denial‑of‑service flaw, which is consistent with the identified activity of halting the system.

Affected Systems

Oracle offers MySQL Server and MySQL Cluster products. Versions 9.7.0 through 9.7.1 of both products are vulnerable. No other supported releases are currently known to be affected.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 indicates a medium‑severe impact focused solely on availability. The EPSS score of less than 1% suggests that, at the time of analysis, exploitation is considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. An adversary can still attempt to exploit the flaw by submitting crafted queries over the network via any of the supported protocols; the attack vector is remote and requires only low‑privilege access. The documented impact allows an attacker to reliably cause service interruption, which may be sufficient to meet malicious objectives such as service disruption or as a pivot for further attacks within an environment that relies on MySQL for critical operations.

Generated by OpenCVE AI on August 4, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MySQL Server or MySQL Cluster to the latest patched release.
  • If an upgrade is not immediately possible, implement strict network controls by proxying or firewalling all connections to the MySQL instances and restricting traffic to only trusted hosts or subnets, thereby limiting low‑privileged attackers’ reach.
  • Enable monitoring of server CPU and memory usage, configure alert thresholds for abnormal spikes, and consider setting conservative resource limits or hardening the optimizer configuration to mitigate repeated crashes when an upgrade cannot be performed.

Generated by OpenCVE AI on August 4, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Optimizer in MySQL Cluster and Server mysql: Optimizer unspecified vulnerability (CPU Jul 2026)
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Optimizer in MySQL Cluster and Server
Weaknesses CWE-770

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:15:31.784Z

Reserved: 2026-07-08T15:51:40.517Z

Link: CVE-2026-60174

cve-icon Vulnrichment

Updated: 2026-07-23T16:15:20.564Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60174 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling