Impact
The vulnerability exists in the NDB Operator component of Oracle MySQL Cluster. It is an improper access control flaw (CWE‑306) that enables a local attacker who has logged on to the host that runs the cluster to bypass the system’s authentication checks and read any data stored in the cluster. With successful exploitation, the attacker can obtain confidential data or even full access to all data managed by the cluster.
Affected Systems
Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected. The flaw specifically targets installations that run the NDB Operator component.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring an attacker to have a user account on the host that runs MySQL Cluster; this limits the exploitability but still poses a confidentiality risk if successful.
OpenCVE Enrichment