PatchSiren cyber security CVE debrief
CVE-2026-60592 Oracle Corporation CVE debrief
The CVE-2026-60592 vulnerability affects the MySQL Cluster product of Oracle MySQL, specifically the Cluster: NDB Operator component. This vulnerability is classified as easily exploitable, allowing an unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. The potential impact includes unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster, as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. The CVSS 3.1 Base Score is 8.2, indicating a High severity level with Integrity and Availability impacts. System administrators and security teams should review the official CVE Program record and NIST NVD detail page for further information and guidance.
- Vendor
- Oracle Corporation
- Product
- MySQL Cluster
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-02
Who should care
System administrators and security teams responsible for MySQL Cluster installations, especially those using affected versions (8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1), should prioritize this vulnerability. The vulnerability's high CVSS score of 8.2 and potential for unauthorized data access and system compromise necessitate immediate attention. Operators, platform administrators, vulnerability management teams, and security teams should collaborate to assess exposure, apply patches or updates, and implement compensating controls as necessary. Additionally, reviewing incident response plans and monitoring for suspicious activity are crucial steps in mitigating the risk associated with this vulnerability. Affected organizations should also verify their inventory of MySQL Cluster deployments and ensure that appropriate defensive measures are in place to prevent exploitation and minimize potential impact on business operations and data integrity. Regularly reviewing and updating security protocols will help maintain a robust security posture against such vulnerabilities. Moreover, defenders should focus on validating the integrity of MySQL Cluster installations, assessing the potential operational impact, and ensuring that all necessary security controls are effectively implemented and monitored. By taking these steps, organizations can reduce the risk of exploitation and protect their assets from potential threats. It is also essential to track exceptions, retest remediated assets, and close the item only after evidence is documented, ensuring a thorough and effective remediation process. Furthermore, defenders should consider implementing additional security measures, such as network access restrictions and enhanced monitoring, to detect and respond to potential security incidents related to this vulnerability. By prioritizing this vulnerability and taking proactive steps to mitigate its risk, organizations can help protect their MySQL Cluster installations and maintain the security and integrity of their data. To ensure the effective management of this vulnerability, it is crucial to establish clear communication channels among relevant stakeholders, ensure
Technical summary
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data.
Defensive priority
High priority due to high CVSS score of 8.2 and potential for unauthorized data access and system compromise.
Recommended defensive actions
- Inventory and verify affected MySQL Cluster versions
- Apply vendor patches or updates
- Implement compensating controls such as network access restrictions
- Monitor for suspicious activity
- Review and update incident response plans
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates vulnerability in MySQL Cluster product of Oracle MySQL. Supported versions affected are 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60592 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60592
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60592 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60592
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspuaug2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.