Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the replication component of Oracle MySQL Server and MySQL Cluster. It allows an attacker who already has high privileges and network access through one of several protocols to successfully execute an exploit that will partially degrade service availability. The damage is limited to a partial denial of service; confidentiality and integrity are not affected. The CVSS vector reflects an accessible network location with high attack complexity and high privileges, resulting in a Base Score of 2.2.

Affected Systems

Affected products are Oracle Corporation MySQL Server and Oracle MySQL Cluster. Specifically, MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. These versions are impacted by the replication flaw described in the CVE.

Risk and Exploitability

With a CVSS score of 2.2 the severity is low and the EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to connect to the affected replication port or protocol and possess high privileged credentials, making the exploit difficult and confined to environments that expose replication traffic or where internal users have elevated privileges. Consequently, the risk is moderate but non‑zero for systems that expose replication services to have privileged users without strict segmentation.

Generated by OpenCVE AI on August 2, 2026 at 23:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MySQL Server to version 8.4.11 or later, or 9.7.2 or later, and upgrade MySQL Cluster to version 8.0.48 or later, or 8.4.11 or later, or 9.7.2 or later.
  • If an upgrade is not immediately possible, restrict replication protocols to trusted hosts only by applying firewall rules and limiting high‑privileged user accounts to necessary replicas.
  • Apply any Oracle security patches or updates that address this replication issue as they become available, and monitor replication logs for abnormal activity to detect potential exploitation attempts.
  • Ensure network segmentation isolates replication traffic from untrusted networks, and enforce least‑privilege access for all replication peers.

Generated by OpenCVE AI on August 2, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Replication Vulnerability in MySQL Server and Cluster mysql: Replication unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Low


Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Replication Vulnerability in MySQL Server and Cluster

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:04:41.342Z

Reserved: 2026-07-08T15:51:40.520Z

Link: CVE-2026-60190

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:50.974Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60190 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-770

    Allocation of Resources Without Limits or Throttling