Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the MySQL Server and MySQL Cluster X Plugin. An unauthenticated attacker can send crafted requests over any of the protocols that the X Plugin listens on, leading to an application hang or a full crash and unauthorized read access to a limited set of data. This information exposure weakness (CWE‑200) and its availability impact allow the attacker to compromise the system without local privileges. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) indicates a high‑severity remote attack.

Affected Systems

Affected Oracle MySQL products include MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1. These versions are listed as supported yet impacted, and the vulnerability requires only network connectivity to the compromised systems.

Risk and Exploitability

The CVSS score of 8.2 signals a high advisory severity that can impact confidentiality and availability. The EPSS score of less than 1 % indicates that exploitation probability is very low, and the vulnerability is not listed in the CISA KEV registry. Based on the description, it is inferred that the attacker can reach the X Plugin from any network interface, does not need to authenticate, and can trigger the failure by sending malicious payloads. Although the actual exploitation likelihood remains low, the potential impact is significant enough to warrant rapid remediation.

Generated by OpenCVE AI on August 4, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's official MySQL security patch from the CPU Jul 2026 advisory to all MySQL Server and MySQL Cluster installations.
  • If an upgrade cannot be performed immediately, disable the X Plugin entirely if it is not required for your environment; otherwise, limit the X Plugin network interface to trusted hosts only by configuring firewall rules to block untrusted networks.
  • Monitor application logs for anomalous X Plugin activity and run host‑based intrusion detection to detect indicators of exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Accessible DoS and Partial Data Disclosure via MySQL Server X Plugin mysql: X Plugin unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-248
References
Metrics threat_severity

None

threat_severity

Important


Fri, 24 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Accessible DoS and Partial Data Disclosure via MySQL Server X Plugin

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:26:52.260Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60315

cve-icon Vulnrichment

Updated: 2026-07-23T19:25:13.692Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60315 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-248

    Uncaught Exception