CVE-2026-60592: High severity Oracle MySQL Cluster vulnerability
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate unauthenticated network exploitation of MySQL Cluster by restricting access to the MySQL Cluster service(s) to trusted network locations only (e.g., via firewall/ACLs) until the affected Oracle MySQL Cluster (NDB Operator) versions can be patched.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are MySQL Cluster 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. The affected component is Cluster: NDB Operator.
Does exploitation require credentials or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access via multiple protocols, with no user interaction required.
What could an attacker accomplish?
An attacker could cause a hang or a frequently repeatable crash resulting in complete denial of service. Successful exploitation can also allow unauthorized update, insert, or delete access to some accessible MySQL Cluster data.