CVE-2026-60187: Medium severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60187?
The severity of CVE-2026-60187 is classified as medium with a CVSS score of 4.4.
How do I fix CVE-2026-60187?
To fix CVE-2026-60187, update your Oracle MySQL Server or MySQL Cluster to a version that is not affected by this vulnerability.
Which versions are affected by CVE-2026-60187?
Affected versions for CVE-2026-60187 include MySQL Server 8.4.0-8.4.10, 9.7.0-9.7.1 and MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1.
What component is affected by CVE-2026-60187?
CVE-2026-60187 affects the MySQL Server component related to Replication.
Is CVE-2026-60187 easy to exploit?
CVE-2026-60187 is considered difficult to exploit despite allowing high privilege access.