Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect exists in the Clone Plugin of Oracle MySQL Server and MySQL Cluster. It allows a high‑privileged attacker with network access through one or more protocols to force the server or cluster into a repeated crash or permanent hang, thereby denying legitimate users the ability to access the database service. The vulnerability has no impact on confidentiality or integrity, and it does not grant attacker access to data. The weakness can be classified as a resource exhaustion or state corruption flaw.

Affected Systems

Affected are Oracle MySQL Server versions 8.4.0‑8.4.10 and 9.7.0‑9.7.1, and Oracle MySQL Cluster versions 8.0.0‑8.0.47, 8.4.0‑8.4.10, and 9.7.0‑9.7.1. The vulnerability was reported for the Clone Plugin component, and only the identified versions are impacted – newer minor releases are absent from the affected range.

Risk and Exploitability

The CVSS score of 4.4 reflects a low‑to‑moderate severity with availability impact only. The EPSS score is less than 1%, indicating a very low likelihood of exploitation in the wild. Because the vulnerability requires a high‑privilege attacker with network access, exploitation opportunities may be limited to privileged insiders or compromised networks. The vulnerability is not yet listed in the CISA KEV catalog. Given the moderate score, the threat is considered permissible but a patch should be applied proactively to avoid potential disruptions.

Generated by OpenCVE AI on August 2, 2026 at 23:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch released in the CPUJul2026 advisory for MySQL Server and MySQL Cluster
  • Disable the Clone Plugin component in MySQL configuration if the functionality is not required to reduce attack surface
  • Restrict network access to the MySQL server and cluster to trusted hosts only, for example by firewalling or using VPC security groups, to limit privileged attack opportunities

Generated by OpenCVE AI on August 2, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Clone Plugin in MySQL Server and Cluster mysql: Clone Plugin unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Clone Plugin in MySQL Server and Cluster
Weaknesses CWE-400

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:03:51.886Z

Reserved: 2026-07-08T15:51:40.519Z

Link: CVE-2026-60182

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60182 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling