Impact
A flaw in the replication component of Oracle MySQL Server and MySQL Cluster allows an attacker who can reach the database over the network to take over the instance. The vulnerability can be exploited by a high‑privileged adversary without user interaction, resulting in complete takeover of the MySQL Server or Cluster. Once compromised, the attacker can read, modify, delete data, and execute arbitrary commands on the underlying host. This leads to a loss of confidentiality, integrity, and availability of the database and any applications that depend on it.
Affected Systems
Affected are Oracle MySQL Server versions 8.4.0‑8.4.10 and 9.7.0‑9.7.1, as well as MySQL Cluster versions 8.0.0‑8.0.47, 8.4.0‑8.4.10, and 9.7.0‑9.7.1. The problem resides in the Server: Replication component of these products.
Risk and Exploitability
The base CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely in the general population but possible for a targeted adversary. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, so no public exploits are currently documented. The attack vector is network‑based on the replication protocols, and an attacker needs prior high privileges on the target to trigger it. Based on the description, it is inferred that the attacker must first have a connection to the MySQL instance; no local privileges are required beyond those granted by replication misconfiguration.
OpenCVE Enrichment