PatchSiren cyber security CVE debrief
CVE-2026-46936 Oracle Corporation CVE debrief
A vulnerability in the MySQL Server and MySQL Cluster product of Oracle MySQL (component: Server: DDL) has been identified. The supported versions affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. This difficult-to-exploit vulnerability allows a high-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server and MySQL Cluster.
- Vendor
- Oracle Corporation
- Product
- MySQL Server
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
System administrators and security teams responsible for MySQL Server and MySQL Cluster installations, particularly those with versions 8.4.0-8.4.10, 9.7.0-9.7.1, 8.0.0-8.0.47, and 8.4.0-8.4.10, should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability is located in the Server: DDL component of MySQL Server and MySQL Cluster. It has a CVSS 3.1 Base Score of 4.4 (Availability impacts) and a CVSS Vector of (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). The vulnerability allows a high-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster, potentially leading to a denial-of-service (DOS) condition.
Defensive priority
Medium priority should be given to patching or mitigating this vulnerability, as it can lead to a DOS condition in MySQL Server and MySQL Cluster.
Recommended defensive actions
- Apply the patches provided by Oracle for MySQL Server and MySQL Cluster versions 8.4.0-8.4.10, 9.7.0-9.7.1, 8.0.0-8.0.47, and 8.4.0-8.4.10.
- Restrict network access to MySQL Server and MySQL Cluster to only necessary personnel.
- Monitor MySQL Server and MySQL Cluster for unusual activity or crashes.
- Consider implementing compensating controls, such as network segmentation or access controls, to limit the attack surface.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-21T22:17:02.160Z and was last modified on 2026-07-27T14:54:30.140Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS 3.1 Base Score of 4.4 (Availability impacts).
Official resources
-
CVE-2026-46936 CVE record
CVE.org
-
CVE-2026-46936 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:02.160Z and has not been modified since then. The NVD entry is currently Analyzed.