Impact
A flaw in the MySQL Server component known as the X Plugin permits a high‑privileged attacker who can reach the server over the network then to immediately compromise the MySQL Server or MySQL Cluster. The vulnerability stems from inadequate access control (CWE‑284) and a privilege escalation weakness (CWE‑648), allowing the attacker to execute arbitrary actions such as dropping privileges and taking full control. The impact encompasses complete loss of confidentiality, integrity and availability of the database services, effectively turning the database into a foothold for broader system compromise.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 are affected by this X Plugin issue.
Risk and Exploitability
The CVSS base score of 7.2 indicates moderate to high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have network reachability to the MySQL instance and high privileges, but once the preconditions are met they can gain full takeover of the MySQL Server or Cluster through the X Plugin interface.
OpenCVE Enrichment