CVE-2026-61094: High severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61094?
The severity of CVE-2026-61094 is rated high with a score of 7.2.
What software is affected by CVE-2026-61094?
CVE-2026-61094 affects Oracle MySQL Server versions 8.4.0 to 8.4.10 and 9.7.0 to 9.7.1, as well as Oracle MySQL Cluster versions 8.0.0 to 8.0.47, 8.4.0 to 8.4.10, and 9.7.0 to 9.7.1.
How do I fix CVE-2026-61094?
To fix CVE-2026-61094, you should upgrade your Oracle MySQL Server and MySQL Cluster to the latest patched versions.
What components of Oracle MySQL are impacted by CVE-2026-61094?
CVE-2026-61094 impacts the Replication component of the MySQL Server and MySQL Cluster products.
Is CVE-2026-61094 easily exploitable?
Yes, CVE-2026-61094 is considered easily exploitable, allowing for high privilege access.