Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle MySQL Connector/J versions 9.7.0 through 9.7.1. It allows a low‑privileged attacker with network reach to exploit the connector and gain unauthorized access to critical data or full access to all data accessible via the connector. The flaw is easily exploitable, with low complexity and no user interaction required, and it escalates the scope to affect related products.

Affected Systems

Oracle MySQL Connector/J, versions 9.7.0–9.7.1.

Risk and Exploitability

The CVSS v3.1 score is 7.7, indicating a high severity with significant confidentiality impact. The EPSS score is below 1%, suggesting a low probability of exploitation at the present time, and the vulnerability is not listed in CISA's KEV catalogue. Attackers can reach the target over the network with low effort and low privileges. The scope change means a successful attack could affect other components that rely on the connector. Given the moderate exploitation probability but high impact, the risk remains significant and should be addressed promptly.

Generated by OpenCVE AI on August 5, 2026 at 01:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MySQL Connector/J to a non‑affected version (≥ 9.7.2).
  • Restrict external network access to the Connector/J service using firewalls or VPNs to limit exposure to trusted hosts.
  • Apply least privilege to database accounts used by Connector/J to reduce the surface area of the attack.

Generated by OpenCVE AI on August 5, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Network Exploit in MySQL Connector/J 9.7.0–9.7.1

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Enables Unauthorized Data Access in MySQL Connector/J
Weaknesses CWE-284

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Enables Unauthorized Data Access in MySQL Connector/J
Weaknesses CWE-284

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle MySQL Connector/J Leading to Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle MySQL Connector/J Leading to Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Wed, 22 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connector/j
Oracle mysql Connectors
Vendors & Products Oracle mysql Connector/j
Oracle mysql Connectors

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle mysql Connector\/j
CPEs cpe:2.3:a:oracle:mysql_connector\/j:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/j
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Mysql Connector/j Mysql Connector\/j Mysql Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T18:19:01.584Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60586

cve-icon Vulnrichment

Updated: 2026-07-29T18:18:58.775Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function