Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MySQL Server and MySQL Cluster contain a flaw in the Optimizer that can be triggered by crafted requests sent over any supported database protocol. When an attacker with low privilege sends these requests, the optimizer may hang or crash, preventing legitimate users from accessing the database. The flaw causes a loss of availability while confidentiality and integrity are not affected. The defect is characterized as a resource exhaustion issue (CWE‑400) and an insufficient resources error (CWE‑770).

Affected Systems

Oracle MySQL Server and Oracle MySQL Cluster are impacted in versions 9.7.0 and 9.7.1. All deployments running these releases are vulnerable unless upgraded or patched.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity with a high availability impact. The EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker should be able to exploit this weakness by sending underprivileged traffic over any of the supported network protocols; a successful exploit will induce a crash or hang that consumes server resources and denies continuous service to legitimate users.

Generated by OpenCVE AI on August 4, 2026 at 04:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or upgrade to a version newer than 9.7.1
  • Limit network exposure of MySQL instances, restricting protocol access to trusted users
  • Enable detailed logging and monitor for abnormal query patterns or frequent crashes

Generated by OpenCVE AI on August 4, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Denial of Service in MySQL Server and Cluster Optimizer via Low-Privilege Attacks mysql: Optimizer unspecified vulnerability (CPU Jul 2026)
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Denial of Service in MySQL Server and Cluster Optimizer via Low-Privilege Attacks
Weaknesses CWE-770

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:57:56.235Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60324

cve-icon Vulnrichment

Updated: 2026-07-23T18:57:31.437Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60324 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling