Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mysql84-serverUpgrade mysql97-serverUpgrade mysql84-clientUpgrade mysql97-client | Aug 7, 2026 | Aug 5, 2026 |
| Oracle Mysql | — | Upgrade to MySQL version 8.4.11Upgrade to MySQL version 9.7.2 | Jul 22, 2026 | Jul 21, 2026 |
| Redhat_linux | — | Upgrade mecab-ipadic-EUCJPUpgrade mysql8.4-commonUpgrade mysql8.4-serverUpgrade mysql8.4Upgrade perl-DBD-MySQL-debugsourceUpgrade mysql8.4-libsUpgrade mysql-devel-debuginfoUpgrade mecabUpgrade mysql8.4-debugsourceUpgrade mysql8.4-errmsgUpgrade mysql-debugsourceUpgrade mysql-serverUpgrade mecab-develUpgrade mysql8.4-server-debuginfoUpgrade mysql-server-debuginfoUpgrade mysql8.4-debuginfoUpgrade mysql-test-debuginfoUpgrade perl-DBD-MySQLUpgrade mysql8.4-test-dataUpgrade mysql8.4-testUpgrade mysql-test-dataUpgrade mysql-develUpgrade mecab-ipadicUpgrade mysql8.4-libs-debuginfoUpgrade mysql8.4-test-debuginfoUpgrade mecab-debuginfoUpgrade mysql-debuginfoUpgrade mysqlUpgrade perl-DBD-MySQL-debuginfoUpgrade mysql-testUpgrade mysql-errmsgUpgrade mysql8.4-develUpgrade rapidjson-develUpgrade mecab-debugsourceUpgrade mysql8.4-devel-debuginfoUpgrade mysql-libs-debuginfoUpgrade rapidjson-docUpgrade mysql-libsUpgrade mysql-common | Jul 29, 2026 | Jul 21, 2026 |
| Rocky_linux | — | Upgrade mysql-serverUpgrade mysql-debugsourceUpgrade mysql-libs-debuginfoUpgrade mecab-debuginfoUpgrade mysql-debuginfoUpgrade mysql-test-debuginfoUpgrade mysql-libsUpgrade mysql-devel-debuginfoUpgrade mysql-testUpgrade mecabUpgrade mecab-debugsourceUpgrade perl-DBD-MySQLUpgrade mecab-develUpgrade mecab-ipadic-EUCJPUpgrade mysql-develUpgrade mecab-ipadicUpgrade mysql-server-debuginfoUpgrade rapidjson-develUpgrade perl-DBD-MySQL-debugsourceUpgrade mysqlUpgrade perl-DBD-MySQL-debuginfo | Aug 21, 2026 | Aug 20, 2026 |
| Ubuntu | — | Upgrade mysql-server-8.0Upgrade mysql-server | Aug 31, 2026 | Jul 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jul 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub