Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Server: Clone Plugin of Oracle MySQL. It can allow an attacker who obtains high privileges and network access to cause a hang or repeatable crash of the MySQL Server or MySQL Cluster, resulting in a full denial of service. The exploit requires the attacker to interact with the clone function over one of MySQL’s supported network protocols. The impact is limited to availability; confidentiality and integrity are not affected.

Affected Systems

Affected are Oracle’s MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. All installations of those products that have the Clone Plugin enabled are susceptible.

Risk and Exploitability

The CVSS 3.1 base score is 4.4, indicating a moderate availability risk. The EPSS score is less than 1%, implying a very low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. A high‑privileged attacker with network reach to MySQL services can trigger the flaw to interrupt database availability, but no known remote code execution or data disclosure is possible according to the current advisory.

Generated by OpenCVE AI on August 2, 2026 at 23:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle MySQL Server and MySQL Cluster to a version released after 8.4.10 and 9.7.1 that contains the patch for the Clone Plugin flaw.
  • If the Clone Plugin is not required, disable or uninstall it from the MySQL configuration to remove the attack surface.
  • Restrict network access to MySQL services by configuring firewall rules, allowing only trusted hosts to connect.

Generated by OpenCVE AI on August 2, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Clone Plugin Denial of Service in Oracle MySQL mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Clone Plugin Denial of Service in Oracle MySQL

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:13:38.427Z

Reserved: 2026-07-08T15:51:40.518Z

Link: CVE-2026-60177

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:34.294Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60177 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling