Description
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the NDB Operator component of Oracle MySQL Cluster. It is an improper access control flaw (CWE‑306) that enables a local attacker who has logged on to the host that runs the cluster to bypass the system’s authentication checks and read any data stored in the cluster. With successful exploitation, the attacker can obtain confidential data or even full access to all data managed by the cluster.

Affected Systems

Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected. The flaw specifically targets installations that run the NDB Operator component.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring an attacker to have a user account on the host that runs MySQL Cluster; this limits the exploitability but still poses a confidentiality risk if successful.

Generated by OpenCVE AI on August 5, 2026 at 01:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a fixed version (e.g., 8.0.48+, 8.4.11+, or 9.7.2+ according to the Oracle CPU alert July 2026).
  • Restrict local access rights to the hosts that run MySQL Cluster, ensuring that only trusted administrators can log in and perform privileged operations.
  • If a patch cannot be applied immediately, isolate the MySQL Cluster from untrusted networks, monitor for anomalous activity, and consider disabling the NDB Operator interface until a fix is available.

Generated by OpenCVE AI on August 5, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Oracle MySQL Cluster NDB Operator Allows Unauthorized Data Access

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access in MySQL Cluster NDB Operator
Weaknesses CWE-284

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access in MySQL Cluster NDB Operator
Weaknesses CWE-284

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Vulnerability in Oracle MySQL Cluster NDB Operator Allows Unauthorized Data Access
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Vulnerability in Oracle MySQL Cluster NDB Operator Allows Unauthorized Data Access
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle mysql Cluster
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Mysql Cluster
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T18:19:35.776Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60569

cve-icon Vulnrichment

Updated: 2026-07-29T18:19:32.403Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function