PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60592 Oracle Corporation CVE debrief

The CVE-2026-60592 vulnerability affects the MySQL Cluster product of Oracle MySQL, specifically the Cluster: NDB Operator component. This vulnerability is classified as easily exploitable, allowing an unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. The potential impact includes unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster, as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. The CVSS 3.1 Base Score is 8.2, indicating a High severity level with Integrity and Availability impacts. System administrators and security teams should review the official CVE Program record and NIST NVD detail page for further information and guidance.

Vendor
Oracle Corporation
Product
MySQL Cluster
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-02
Advisory published
2026-08-18
Advisory updated
2026-09-02

Who should care

System administrators and security teams responsible for MySQL Cluster installations, especially those using affected versions (8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1), should prioritize this vulnerability. The vulnerability's high CVSS score of 8.2 and potential for unauthorized data access and system compromise necessitate immediate attention. Operators, platform administrators, vulnerability management teams, and security teams should collaborate to assess exposure, apply patches or updates, and implement compensating controls as necessary. Additionally, reviewing incident response plans and monitoring for suspicious activity are crucial steps in mitigating the risk associated with this vulnerability. Affected organizations should also verify their inventory of MySQL Cluster deployments and ensure that appropriate defensive measures are in place to prevent exploitation and minimize potential impact on business operations and data integrity. Regularly reviewing and updating security protocols will help maintain a robust security posture against such vulnerabilities. Moreover, defenders should focus on validating the integrity of MySQL Cluster installations, assessing the potential operational impact, and ensuring that all necessary security controls are effectively implemented and monitored. By taking these steps, organizations can reduce the risk of exploitation and protect their assets from potential threats. It is also essential to track exceptions, retest remediated assets, and close the item only after evidence is documented, ensuring a thorough and effective remediation process. Furthermore, defenders should consider implementing additional security measures, such as network access restrictions and enhanced monitoring, to detect and respond to potential security incidents related to this vulnerability. By prioritizing this vulnerability and taking proactive steps to mitigate its risk, organizations can help protect their MySQL Cluster installations and maintain the security and integrity of their data. To ensure the effective management of this vulnerability, it is crucial to establish clear communication channels among relevant stakeholders, ensure

Technical summary

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data.

Defensive priority

High priority due to high CVSS score of 8.2 and potential for unauthorized data access and system compromise.

Recommended defensive actions

  • Inventory and verify affected MySQL Cluster versions
  • Apply vendor patches or updates
  • Implement compensating controls such as network access restrictions
  • Monitor for suspicious activity
  • Review and update incident response plans

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page indicates vulnerability in MySQL Cluster product of Oracle MySQL. Supported versions affected are 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60592 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60592

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60592 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60592

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.