Description
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle MySQL Server and MySQL Cluster contain a local privilege escalation flaw in the Group Replication GCS component. An attacker who already has high‑privileged access to the host can trigger the vulnerability and compromise the database instance, leading to full takeover. The exploit results in simultaneous confidentiality, integrity, and availability loss for the affected MySQL services.

Affected Systems

Affected packages are Oracle MySQL Server and Oracle MySQL Cluster. Vulnerable MySQL Server versions are 8.4.0‑8.4.10 and 9.7.0‑9.7.1. Vulnerable MySQL Cluster versions are 8.0.0‑8.0.47, 8.4.0‑8.4.10, and 9.7.0‑9.7.1.

Risk and Exploitability

The CVSS 3.1 base score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw requires local high‑privileged access and does not provide a remote attack vector. Once exploited, the attacker gains complete control over the MySQL instances, potentially exposing, destroying, or modifying sensitive data and disrupting database services. The vulnerability is not listed in CISA’s KEV catalog, but the impact warrants immediate attention if the affected versions are in use.

Generated by OpenCVE AI on August 2, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle MySQL security patch that fixes the Group Replication GCS flaw
  • Upgrade to a non‑vulnerable release beyond 8.4.10, 9.7.1, or 8.0.47
  • Restrict operating‑system accounts that can execute the MySQL server process to trusted users and limit local high‑privileged access
  • Monitor database and system logs for anomalous Group Replication activity and alert on repeated executions

Generated by OpenCVE AI on August 2, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle MySQL Server/Cluster via Group Replication mysql: Group Replication GCS unspecified vulnerability (CPU Jul 2026)
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle MySQL Server/Cluster via Group Replication

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mysql Cluster
Oracle mysql Server
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
Oracle mysql Server
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mysql Cluster Mysql Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:38.228Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60332

cve-icon Vulnrichment

Updated: 2026-07-24T14:12:21.027Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T00:00:00Z

Links: CVE-2026-60332 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:00:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control