PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60317 Oracle Corporation CVE debrief

A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/Net component. The vulnerability has a CVSS score of 7.4 and can allow an unauthenticated attacker with network access to compromise MySQL Connectors, potentially leading to unauthorized creation, deletion, or modification of critical data. This vulnerability affects MySQL Connectors versions 9.7.0-9.7.1 and has a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N. The vulnerability is difficult to exploit and requires network access via multiple protocols. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data.

Vendor
Oracle Corporation
Product
MySQL Connectors
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-25
Advisory published
2026-07-21
Advisory updated
2026-07-25

Who should care

Organizations using MySQL Connectors, particularly versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes reviewing their current deployments, assessing potential impacts, and prioritizing patching or updates accordingly. Additionally, defenders should verify the presence of affected MySQL Connectors installations and implement network access controls to limit access to MySQL Connectors.

Technical summary

The vulnerability, CVE-2026-60317, affects MySQL Connectors versions 9.7.0-9.7.1 and has a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N. It allows an unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors, potentially leading to unauthorized creation, deletion, or modification access to critical data or all MySQL Connectors accessible data, as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data.

Defensive priority

High priority should be given to patching or mitigating this vulnerability, as it can have significant impacts on data confidentiality and integrity. Defenders should verify the presence of affected MySQL Connectors installations and prioritize patching or updates accordingly.

Recommended defensive actions

  • Apply patches or updates provided by the vendor to vulnerable MySQL Connectors installations.
  • Implement network access controls to limit access to MySQL Connectors.
  • Monitor MySQL Connectors installations for suspicious activity.
  • Consider compensating controls, such as additional authentication or authorization mechanisms.
  • Review and update incident response plans to address potential impacts of this vulnerability.
  • Perform vulnerability scanning and asset inventory to identify affected systems.
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved.

Evidence notes

The CVE record was published on 2026-07-21T22:17:34.510Z and was last modified on 2026-07-25T05:16:37.930Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability. Further verification is needed to confirm affected deployments and assess potential impacts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:34.510Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.