CVE-2026-61081: Infoleak
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MySQL Serverto a version that resolves this vulnerability.Fixed in 8.4.10 - Upgrade
Upgrade
MySQL Serverto a version that resolves this vulnerability.Fixed in 9.7.1 - Upgrade
Upgrade
MySQL Clusterto a version that resolves this vulnerability.Fixed in 8.0.47 - Upgrade
Upgrade
MySQL Clusterto a version that resolves this vulnerability.Fixed in 8.4.10 - Upgrade
Upgrade
MySQL Clusterto a version that resolves this vulnerability.Fixed in 9.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61081?
CVE-2026-61081 has a severity rating of low, with a score of 2.7 on the CVSS scale.
Which versions of MySQL Server are affected by CVE-2026-61081?
Affected versions of MySQL Server include 8.4.0 to 8.4.10 and 9.7.0 to 9.7.1.
How do I fix CVE-2026-61081?
To mitigate CVE-2026-61081, it is recommended to upgrade to the latest supported version of MySQL Server.
What type of vulnerability is CVE-2026-61081?
CVE-2026-61081 is classified as an information leak vulnerability.
Is CVE-2026-61081 easily exploitable?
Yes, CVE-2026-61081 is considered easily exploitable, especially with high privileges.