Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Configurator component of Oracle MySQL Server and Oracle MySQL Cluster. It allows a low‑privileged user who has logged into the host machine to compromise the database instance, potentially gaining full control over data, configuration, and availability. The flaw is a manifestation of insufficient authorization controls (CWE-284) and an improper handling of configuration parameters (CWE-15). Successful exploitation would let an attacker read, modify, or delete data and maintain persistent access to the affected MySQL service.

Affected Systems

Oracle MySQL Server and Oracle MySQL Cluster versions 9.7.0 through 9.7.1 are affected. No other product versions are mentioned as vulnerable.

Risk and Exploitability

The flaw carries a CVSS 3.1 base score of 6.7, reflecting significant confidentiality, integrity, and availability impacts. Its EPSS score is below 1 %, indicating a low probability of zero‑day exploitation. The vulnerability is not listed in CISA’s KEV catalog and requires the attacker to have a local login on the system and an additional human interaction from a separate individual, such as an insider or compromised credential holder. While exploitation is non‑remote and requires human action, the potential for complete takeover makes it a high‑impact threat if achieved.

Generated by OpenCVE AI on August 4, 2026 at 04:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle MySQL security patch released in July 2026 that addresses versions 9.7.0‑9.7.1.
  • Upgrade to a version newer than 9.7.1, such as 9.8.x or later, when available.
  • Restrict local login privileges on systems running MySQL, ensuring that only authorized accounts with full DBA rights can execute the Configurator.

Generated by OpenCVE AI on August 4, 2026 at 04:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title MySQL Server and Cluster Local Privilege Escalation Allowing Takeover mysql: Configurator unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-15
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title MySQL Server and Cluster Local Privilege Escalation Allowing Takeover
Weaknesses CWE-269

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:10.647Z

Reserved: 2026-07-08T15:51:40.519Z

Link: CVE-2026-60181

cve-icon Vulnrichment

Updated: 2026-07-23T15:05:18.265Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60181 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting

  • CWE-284

    Improper Access Control