Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Clone Plugin component of Oracle MySQL Server and MySQL Cluster. A high‑privileged attacker with network access via multiple protocols can exploit the plugin to compromise the server, thereby gaining full control over the database instance. Successful exploitation results in disclosure and modification of all data, loss of availability, and complete administrative takeover, with high impacts on confidentiality, integrity, and availability as reflected in the CVSS score.

Affected Systems

Oracle Corporation products affected include MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. If one of these versions is installed, the system is vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 indicates moderate risk with high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need network access and the ability to communicate over the supported protocols to reach the Clone Plugin. No local privilege escalation is described, so the threat is remote but requires a high‑privileged attacker with network access via multiple protocols.

Generated by OpenCVE AI on August 2, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch or upgrade to a non‑affected release of MySQL Server or MySQL Cluster.
  • Disable the Clone Plugin if it is not required for your deployment.
  • Restrict network access to the MySQL ports to only trusted hosts using firewall rules and network segmentation.

Generated by OpenCVE AI on August 2, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-286

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Takeover via Clone Plugin in Oracle MySQL mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-648
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Takeover via Clone Plugin in Oracle MySQL
Weaknesses CWE-285
CWE-286

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:09.729Z

Reserved: 2026-07-08T15:51:40.518Z

Link: CVE-2026-60178

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:01.067Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60178 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-648

    Incorrect Use of Privileged APIs