Impact
A flaw in the Pluggable Auth component of Oracle MySQL Server and MySQL Cluster enables an attacker who has access to the underlying host to modify database contents. The vulnerability does not reveal data or interrupt service; it only permits unauthorized updates, inserts, or deletes, thereby compromising data integrity. The weakness is an improper access control failure (CWE‑284).
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected. All other releases are not listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 2.9 indicates low severity, and an EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability requires local access to the machine hosting MySQL, so remote exploitation is not possible. The risk level is low and the issue is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment