Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the replication handling of Oracle MySQL Server and MySQL Cluster, categorized as CWE-400 and CWE-770, allows a high‑privileged attacker with network access to trigger a difficult‑to‑exploit crash or hang of the database service. This results in a denial of service that renders the system unavailable, without compromising confidentiality or integrity.

Affected Systems

Oracle MySQL Server and Oracle MySQL Cluster are affected. Versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 of MySQL Server, and 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 of MySQL Cluster, all run the vulnerable code and are potentially affected.

Risk and Exploitability

The CVSS 3.1 Base Score of 4.4 indicates low severity, with high attack complexity and required privileges. The EPSS score of <1 % suggests a very low exploitation probability, and the vulnerability is not listed in CISA KEV. An attacker must be able to access the MySQL instance over any supported network protocol and possess sufficient privileges to influence replication traffic; once these conditions are met, a crash or hang can be induced that brings the service down until it is restarted.

Generated by OpenCVE AI on August 4, 2026 at 04:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MySQL Server or MySQL Cluster to a patched release from Oracle when it becomes available.
  • If an upgrade is not immediately possible, limit replication traffic by configuring firewall rules or MySQL user privileges so that only trusted hosts can connect to the replication ports (default 3306).
  • Temporarily disable replication by setting options such as skip-slave-start in the configuration file and restarting MySQL; resume replication only after the patched version is applied.

Generated by OpenCVE AI on August 4, 2026 at 04:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title mysql: Replication unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:02:23.352Z

Reserved: 2026-07-08T15:51:40.519Z

Link: CVE-2026-60184

cve-icon Vulnrichment

Updated: 2026-07-23T15:02:15.770Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60184 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling