Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle MySQL Connector/Net allows a low‑privileged attacker with network access to exploit the connector through multiple protocols, potentially taking full control of the Connector/Net process and all data it handles. Successful exploitation results in loss of confidentiality, integrity, and availability for data processed by the connector, and the scope change indicates that other dependent components could also be affected.

Affected Systems

Affected vendor: Oracle Corporation. Product: MySQL Connector/Net. Affected versions are 9.7.0 and 9.7.1. Because the vulnerability has a scope change, an attacker who compromises the connector can potentially affect additional products or components that rely on or interact with the connector. This means that other applications or services using the affected connector may also be at risk.

Risk and Exploitability

The CVSS vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H shows a network‑based attack with high complexity and low privilege. The EPSS score of <1% indicates a low current exploitation probability, and the vulnerability is not listed in CISA KEV. However, the scope change and potential for full takeover make this a high‑severity risk for deployments of the affected connector versions.

Generated by OpenCVE AI on August 2, 2026 at 23:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that updates MySQL Connector/Net to a version newer than 9.7.1.
  • Restrict network exposure of the connector by configuring firewalls or VPNs to allow inbound traffic only from trusted sources.
  • Enforce least‑privilege for any accounts or service principals used by the connector, disabling unused authentication mechanisms.
  • Monitor connector logs for anomalous connection or authentication activity and investigate suspicious events promptly.

Generated by OpenCVE AI on August 2, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title MySQL Connector/Net Vulnerability Enabling Low‑Privileged Network Takeover

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Network‑Based Exploit Enabling Full Compromise of MySQL Connector/Net
Weaknesses CWE-269

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Network‑Based Exploit Enabling Full Compromise of MySQL Connector/Net
Weaknesses CWE-269

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connector/net
Oracle mysql Connectors
Vendors & Products Oracle mysql Connector/net
Oracle mysql Connectors

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Connector\/net
CPEs cpe:2.3:a:oracle:mysql_connector\/net:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/net
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Connector/net Mysql Connector\/net Mysql Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:14.842Z

Reserved: 2026-07-08T15:51:40.520Z

Link: CVE-2026-60193

cve-icon Vulnrichment

Updated: 2026-07-23T16:16:11.219Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses