Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the replication component of Oracle MySQL Server and Cluster permits a high privileged attacker who has logged into the host that runs MySQL to gain full control of the database instance. By exploiting this flaw an attacker can compromise the confidentiality, integrity, and availability of all data managed by MySQL. The flaw is characterized by a CVSS v3.1 base score of 6.4 with a vector indicating local attack, high attack complexity, and high privileges.

Affected Systems

Affected products include Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as Oracle MySQL Cluster versions 8.0.0 to 8.0.47, 8.4.0 to 8.4.10, and 9.7.0 to 9.7.1. Any deployment using these versions that runs a replication component is subject to the risk described.

Risk and Exploitability

Although the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, the impact of a successful exploitation is significant. The exploit requires that the attacker already has local high‑privileged access to the host; from there the compromised MySQL instance can be taken over. The moderate CVSS score indicates a meaningful risk, and due to the severe consequences, timely remediation is recommended.

Generated by OpenCVE AI on August 2, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MySQL Server or MySQL Cluster to a patched version that addresses this issue—specific version numbers are not provided in the advisory.
  • Restrict local accounts on the host that can start or manage the MySQL service to the minimum required.
  • If replication is not needed, disable the replication component; otherwise enforce strong authentication for replication connections.

Generated by OpenCVE AI on August 2, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Replication in MySQL Server and Cluster mysql: Replication unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Replication in MySQL Server and Cluster
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:37.339Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60331

cve-icon Vulnrichment

Updated: 2026-07-24T13:04:44.166Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60331 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:00:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control