Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the MySQL Server component known as the X Plugin permits a high‑privileged attacker who can reach the server over the network then to immediately compromise the MySQL Server or MySQL Cluster. The vulnerability stems from inadequate access control (CWE‑284) and a privilege escalation weakness (CWE‑648), allowing the attacker to execute arbitrary actions such as dropping privileges and taking full control. The impact encompasses complete loss of confidentiality, integrity and availability of the database services, effectively turning the database into a foothold for broader system compromise.

Affected Systems

Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 are affected by this X Plugin issue.

Risk and Exploitability

The CVSS base score of 7.2 indicates moderate to high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have network reachability to the MySQL instance and high privileges, but once the preconditions are met they can gain full takeover of the MySQL Server or Cluster through the X Plugin interface.

Generated by OpenCVE AI on August 4, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle July 2026 Cumulative Update that contains the X Plugin fix
  • Limit access to MySQL Server and Cluster by configuring firewall rules or VPN restrictions so only trusted hosts can reach X Plugin interfaces
  • Revoke or limit excessive privileges for MySQL accounts, ensuring no user has high‑level rights that could be abused via the plugin
  • Monitor MySQL authentication and privilege‑change logs for anomalous activity and enforce audit logging to detect exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title mysql: X Plugin unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-648
References
Metrics threat_severity

None

threat_severity

Important


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of MySQL Server and Cluster via X Plugin Vulnerability
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Takeover of MySQL Server and Cluster via X Plugin Vulnerability
Weaknesses CWE-284
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:33.319Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60316

cve-icon Vulnrichment

Updated: 2026-07-23T19:28:58.191Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60316 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-648

    Incorrect Use of Privileged APIs