CVE-2026-47008: Medium severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected and what is the operational impact?
Systems running MySQL Server or MySQL Cluster versions 9.7.0 through 9.7.1 are identified as affected. The impact is limited to availability: an attacker may cause a hang or a repeatable crash resulting in a complete denial of service.
What level of access does an attacker need?
Exploitation requires a high-privileged attacker who has network access to the affected MySQL Server or MySQL Cluster instance. No user interaction is required, and the vulnerability is described as easily exploitable through multiple protocols.
What should teams do if they cannot update immediately?
The provided information does not identify a workaround or mitigation. Prioritize updating affected 9.7.0-9.7.1 deployments, and until then restrict network access and limit high-privileged database access to trusted administrators.