CVE-2026-61109: Medium severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61109?
The severity of CVE-2026-61109 is medium with a CVSS score of 6.5.
What are the affected versions for CVE-2026-61109?
CVE-2026-61109 affects MySQL Server versions 8.4.0-8.4.10 and 9.7.0-9.7.1, as well as MySQL Cluster versions 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1.
How can I mitigate CVE-2026-61109?
Mitigation for CVE-2026-61109 involves updating to a version of MySQL Server or MySQL Cluster that is not affected by this vulnerability.
What is the nature of the vulnerability in CVE-2026-61109?
CVE-2026-61109 is an easily exploitable vulnerability that allows low privileged attackers to cause denial of service.
Is there a known fix for CVE-2026-61109?
The recommended fix for CVE-2026-61109 is to upgrade to the latest patched versions of the affected MySQL software.