CVE-2026-60718: Medium severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle MySQL (Server: JSON)to a version that resolves this vulnerability.Fixed in 9.7.0-9.7.1 - Compensating control
Apply a network-level mitigation for MySQL Server/MySQL Cluster to prevent low-privileged remote attackers from reaching the exposed MySQL services (e.g., restrict inbound access to the MySQL ports/protocols to only trusted networks/hosts).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60718?
The severity of CVE-2026-60718 is classified as medium with a score of 6.5.
How do I fix CVE-2026-60718?
To fix CVE-2026-60718, upgrade your MySQL Server and MySQL Cluster to versions 9.7.2 or later.
What components are affected by CVE-2026-60718?
CVE-2026-60718 affects the MySQL Server and MySQL Cluster products, specifically the Server: JSON component.
What versions of MySQL are vulnerable to CVE-2026-60718?
The vulnerable versions of MySQL are 9.7.0 and 9.7.1.
Who can exploit CVE-2026-60718?
CVE-2026-60718 can be exploited by a low-privileged attacker with network access.