PatchSiren cyber security CVE debrief
CVE-2026-60317 Oracle Corporation CVE debrief
A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/Net component. The vulnerability has a CVSS score of 7.4 and can allow an unauthenticated attacker with network access to compromise MySQL Connectors, potentially leading to unauthorized creation, deletion, or modification of critical data. This vulnerability affects MySQL Connectors versions 9.7.0-9.7.1 and has a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N. The vulnerability is difficult to exploit and requires network access via multiple protocols. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data.
- Vendor
- Oracle Corporation
- Product
- MySQL Connectors
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-25
Who should care
Organizations using MySQL Connectors, particularly versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes reviewing their current deployments, assessing potential impacts, and prioritizing patching or updates accordingly. Additionally, defenders should verify the presence of affected MySQL Connectors installations and implement network access controls to limit access to MySQL Connectors.
Technical summary
The vulnerability, CVE-2026-60317, affects MySQL Connectors versions 9.7.0-9.7.1 and has a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N. It allows an unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors, potentially leading to unauthorized creation, deletion, or modification access to critical data or all MySQL Connectors accessible data, as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it can have significant impacts on data confidentiality and integrity. Defenders should verify the presence of affected MySQL Connectors installations and prioritize patching or updates accordingly.
Recommended defensive actions
- Apply patches or updates provided by the vendor to vulnerable MySQL Connectors installations.
- Implement network access controls to limit access to MySQL Connectors.
- Monitor MySQL Connectors installations for suspicious activity.
- Consider compensating controls, such as additional authentication or authorization mechanisms.
- Review and update incident response plans to address potential impacts of this vulnerability.
- Perform vulnerability scanning and asset inventory to identify affected systems.
- Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved.
Evidence notes
The CVE record was published on 2026-07-21T22:17:34.510Z and was last modified on 2026-07-25T05:16:37.930Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability. Further verification is needed to confirm affected deployments and assess potential impacts.
Official resources
-
CVE-2026-60317 CVE record
CVE.org
-
CVE-2026-60317 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:34.510Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.