Description
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle MySQL Connector/J allows an unauthenticated attacker with network access, using several protocols, to gain unauthorized access to data stored in MySQL connectors. The issue requires human interaction from a person other than the attacker to complete the exploitation. If successful, the attacker can read critical data or obtain full access to all data that the connector manages. The weakness is an improper privilege management flaw that could expose sensitive information. The vulnerability encompasses multiple weaknesses, including missing authentication (CWE‑200), improper privilege management (CWE‑285), cross‑site request forgery (CWE‑352), and open redirect (CWE‑601).

Affected Systems

Oracle Corporation’s MySQL Connector/J component is affected. The vulnerability applies to supported versions 9.7.0 through 9.7.1, which are commonly used in Java applications that connect to MySQL databases.

Risk and Exploitability

The CVSS score is 6.5, indicating a medium severity impact, and the EPSS score is less than 1%, suggesting a very low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers are likely to reach the vulnerable connector over a network that exposes the supported protocols, and while successful attacks require human interaction, the risk remains for organizations that run the affected version. The overall risk is moderate but does not warrant an emergency situation given the low EPSS, yet it should be addressed promptly to prevent data breach.

Generated by OpenCVE AI on August 2, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Connector/J to a version beyond 9.7.1 that contains the fix
  • Restrict network access to the connector by applying firewall rules or VPNs so that only trusted hosts can reach it
  • Enforce strong authentication and encryption on all database connections and remove any unauthenticated connections

Generated by OpenCVE AI on August 2, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Multiple Weaknesses in Oracle MySQL Connector/J Allow Unauthorized Data Access

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access in Oracle MySQL Connector/J Allows Data Exfiltration
Weaknesses CWE-284

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access in Oracle MySQL Connector/J Allows Data Exfiltration
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285
CWE-352
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connector/j
Oracle mysql Connectors
Vendors & Products Oracle mysql Connector/j
Oracle mysql Connectors

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle mysql Connector\/j
CPEs cpe:2.3:a:oracle:mysql_connector\/j:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/j
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Mysql Connector/j Mysql Connector\/j Mysql Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:42.805Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61082

cve-icon Vulnrichment

Updated: 2026-07-23T19:14:58.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:39.093

Modified: 2026-08-03T15:17:26.203

Link: CVE-2026-61082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')