Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle MySQL Connector/Net allows an unauthenticated attacker with network access to create, delete, or modify data without first authenticating. The flaw can lead to unauthorized access or complete control over all Connector/Net‑exposed data, directly compromising confidentiality and integrity. The condition for exploitation is difficult, yet bypasses all authentication safeguards.

Affected Systems

Oracle MySQL Connector/Net versions 9.7.0 through 9.7.1 are affected. Systems using these components, across any supported platform, are at risk if the Connector/Net library is present and reachable over the network.

Risk and Exploitability

The CVSS v3.1 score of 7.4 highlights significant impact to confidentiality and integrity, though availability is not affected. The EPSS score of less than 1% indicates very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is network‑based, with no authentication required, making it a serious risk for exposed services. By exploiting the flaw an attacker can potentially gain unrestricted access to critical data managed by Connector/Net.

Generated by OpenCVE AI on August 4, 2026 at 04:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle MySQL Connector/Net 9.7.0‑9.7.1 as released by Oracle.
  • Upgrade to a non‑affected Connector/Net version if a patch is not available.
  • Implement network segmentation or firewall rules to restrict inbound traffic to Connector/Net endpoints only to trusted hosts.
  • Enforce strong authentication and disable unused protocols on the affected systems to reduce attack surface.

Generated by OpenCVE AI on August 4, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit Enables Arbitrary Data Modification in Oracle MySQL Connector/Net

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit Enables Arbitrary Data Modification in Oracle MySQL Connector/Net

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via MySQL Connector/Net
Weaknesses CWE-693

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via MySQL Connector/Net
Weaknesses CWE-284
CWE-693

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle mysql Connector\/net
CPEs cpe:2.3:a:oracle:mysql_connector\/net:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/net
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Mysql Connector\/net
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:15.746Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60317

cve-icon Vulnrichment

Updated: 2026-07-23T19:34:31.892Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses