Impact
Oracle MySQL Server and MySQL Cluster contain a local privilege escalation flaw in the Group Replication GCS component. An attacker who already has high‑privileged access to the host can trigger the vulnerability and compromise the database instance, leading to full takeover. The exploit results in simultaneous confidentiality, integrity, and availability loss for the affected MySQL services.
Affected Systems
Affected packages are Oracle MySQL Server and Oracle MySQL Cluster. Vulnerable MySQL Server versions are 8.4.0‑8.4.10 and 9.7.0‑9.7.1. Vulnerable MySQL Cluster versions are 8.0.0‑8.0.47, 8.4.0‑8.4.10, and 9.7.0‑9.7.1.
Risk and Exploitability
The CVSS 3.1 base score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw requires local high‑privileged access and does not provide a remote attack vector. Once exploited, the attacker gains complete control over the MySQL instances, potentially exposing, destroying, or modifying sensitive data and disrupting database services. The vulnerability is not listed in CISA’s KEV catalog, but the impact warrants immediate attention if the affected versions are in use.
OpenCVE Enrichment