Description
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access can trigger the vulnerability in MySQL Cluster’s NDB Operator component, causing the cluster to hang or repeatedly crash, which results in a denial of service. The flaw also permits unauthorized updates, inserts, or deletes on data exposed through the cluster, thereby compromising data integrity. The weakness is a classic example of improper access control (CWE-284), reflected in the CVSS 3.1 base score of 8.2 that highlights integrity and availability impacts.

Affected Systems

The vulnerability affects Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. It resides in the Cluster: NDB Operator component and is reachable via multiple network protocols, without requiring authentication.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity issue. Although the EPSS score is less than 1 %, the lack of authentication and direct network reachability provide a strong incentive for attackers, and the potential to cause both service disruption and data tampering make this vulnerability a significant threat. The vulnerability is not listed in CISA’s KEV catalog, but its impact and easy exploitation path justify immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 16:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a MySQL Cluster release that excludes the affected versions (⩾ 8.0.48, 8.4.11, 9.7.2).
  • Restrict inbound traffic to cluster nodes by implementing firewall rules or VLAN segmentation to limit access to trusted IP addresses only.
  • Enable comprehensive logging and regularly audit write operations, cluster health metrics, and any repeated crash events to detect exploitation attempts early.

Generated by OpenCVE AI on August 21, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Vulnerability in MySQL Cluster Allowing Unauthorized Data Modification and Denial of Service

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle mysql Cluster
CPEs cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Cluster
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Mysql Cluster
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:33:43.961Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60592

cve-icon Vulnrichment

Updated: 2026-08-20T17:33:29.233Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:38.603

Modified: 2026-09-02T17:54:20.903

Link: CVE-2026-60592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:15:03Z

Weaknesses