Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mysql97-clientUpgrade mysql84-serverUpgrade mysql97-serverUpgrade mysql84-client | Aug 7, 2026 | Aug 5, 2026 |
| Oracle Mysql | — | Upgrade to MySQL version 8.4.11Upgrade to MySQL version 9.7.2 | Jul 22, 2026 | Jul 21, 2026 |
| Redhat_linux | — | Upgrade mysql-test-debuginfoUpgrade mysql-libsUpgrade mysql8.4-devel-debuginfoUpgrade rapidjson-docUpgrade perl-DBD-MySQLUpgrade mecab-ipadicUpgrade mysql8.4-commonUpgrade mysql-testUpgrade perl-DBD-MySQL-debugsourceUpgrade mysql-server-debuginfoUpgrade mecab-ipadic-EUCJPUpgrade mysql-test-dataUpgrade mecab-develUpgrade perl-DBD-MySQL-debuginfoUpgrade mysql8.4-libs-debuginfoUpgrade rapidjson-develUpgrade mysql8.4-errmsgUpgrade mecab-debuginfoUpgrade mysql8.4-libsUpgrade mecab-debugsourceUpgrade mysql-debuginfoUpgrade mysql-debugsourceUpgrade mecabUpgrade mysql8.4-test-dataUpgrade mysql8.4-develUpgrade mysql8.4-debugsourceUpgrade mysql8.4-serverUpgrade mysql8.4Upgrade mysqlUpgrade mysql8.4-testUpgrade mysql8.4-test-debuginfoUpgrade mysql-commonUpgrade mysql-serverUpgrade mysql8.4-debuginfoUpgrade mysql-libs-debuginfoUpgrade mysql8.4-server-debuginfoUpgrade mysql-errmsgUpgrade mysql-devel-debuginfoUpgrade mysql-devel | Jul 29, 2026 | Jul 21, 2026 |
| Rocky_linux | — | Upgrade mecabUpgrade perl-DBD-MySQLUpgrade mecab-ipadicUpgrade mysql-devel-debuginfoUpgrade mysqlUpgrade mysql-testUpgrade mecab-debuginfoUpgrade mysql-debugsourceUpgrade mecab-ipadic-EUCJPUpgrade rapidjson-develUpgrade mysql-serverUpgrade mysql-libsUpgrade perl-DBD-MySQL-debugsourceUpgrade mysql-develUpgrade mysql-server-debuginfoUpgrade mysql-libs-debuginfoUpgrade mysql-debuginfoUpgrade mecab-develUpgrade perl-DBD-MySQL-debuginfoUpgrade mecab-debugsourceUpgrade mysql-test-debuginfo | Aug 21, 2026 | Aug 20, 2026 |
| Ubuntu | — | Upgrade mysql-server-8.0Upgrade mysql-server | Aug 31, 2026 | Jul 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jul 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub