CVE-2026-60585: Medium severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60585?
CVE-2026-60585 has a medium severity rating of 6.6.
How do I fix CVE-2026-60585?
To address CVE-2026-60585, upgrade MySQL Server to version 8.4.11 or later, or to 9.7.2 or later.
Which MySQL versions are affected by CVE-2026-60585?
CVE-2026-60585 affects MySQL Server versions 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster versions 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1.
What components are involved in CVE-2026-60585?
CVE-2026-60585 involves a vulnerability in the Server: Replication component of the MySQL Server and MySQL Cluster products.
Is CVE-2026-60585 easy to exploit?
CVE-2026-60585 is considered difficult to exploit due to its requirements for high privileges.