Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle's MySQL Connector/C++ that allows an unauthenticated attacker to perform unauthorized creation, deletion, or modification of critical data. The flaw also enables the attacker to access all data exposed by the MySQL Connector instances, compromising confidentiality and integrity of the information. The weakness is an authentication bypass, in which software incorrectly verifies or fails to verify credentials before granting data manipulation rights.

Affected Systems

Oracle Corporation MySQL Connectors, specifically Connector/C++. The affected versions are 9.7.0 through 9.7.1. Users running these releases are vulnerable; later releases are not impacted according to the supplied information.

Risk and Exploitability

The CVSS v3.1 score of 7.4 indicates high severity, and the EPSS score below 1% suggests that exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network-based and does not require user interaction, meaning remote attackers can exploit the flaw without local access. Successful exploitation results in full control over the data surfaces that the connector exposes, which can lead to significant operational or data breaches if the connector is used on critical infrastructure.

Generated by OpenCVE AI on August 4, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MySQL Connector/C++ release that excludes versions 9.7.0–9.7.1 or install the vendor-provided security patch.
  • If an immediate update is not available, restrict network access to the Connector/C++ using firewall rules or VIP-based network segmentation, ensuring that only trusted hosts can reach the affected ports.
  • Continuously audit Connector/C++ logs for suspicious authentication failures or unauthorized data access attempts, and review account permissions to enforce least privilege on any exposed services.

Generated by OpenCVE AI on August 4, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle MySQL Connector/C++ Allows Unauthorized Data Modification

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle MySQL Connector/C++ Allows Unauthorized Data Modification

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access via MySQL Connector/C++ Vulnerability
Weaknesses CWE-285

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access via MySQL Connector/C++ Vulnerability
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connectors
Weaknesses CWE-284
Vendors & Products Oracle mysql Connectors
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle mysql Connector\/c\+\+
CPEs cpe:2.3:a:oracle:mysql_connector\/c\+\+:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/c\+\+
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Mysql Connector\/c\+\+ Mysql Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:14.065Z

Reserved: 2026-07-08T15:51:40.518Z

Link: CVE-2026-60179

cve-icon Vulnrichment

Updated: 2026-07-23T16:16:08.184Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses