CVE-2026-61128
MySQL vulnerability analysis and mitigation

Overview

CVE-2026-61128 is a Denial of Service vulnerability in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster, affecting versions 9.7.0 through 9.7.1. It was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. The vulnerability allows a high-privileged attacker with network access to cause the database server to hang or crash repeatedly, resulting in a complete denial of service. It carries a CVSS v3.1 base score of 4.9 (Medium) (Oracle Advisory).

Technical details

The vulnerability resides in the Server: Optimizer component of MySQL Server and MySQL Cluster, classified as an availability-impacting flaw (CWE category consistent with improper input handling leading to server crash). An attacker with high privileges and network access can send crafted queries or optimizer-triggering inputs via multiple supported protocols (e.g., MySQL protocol, TCP/IP) that cause the server to hang or crash in a frequently repeatable manner. No authentication bypass is involved — the attacker must already hold high-privileged database credentials. No public technical write-up or proof-of-concept code has been identified at this time (Oracle Advisory).

Impact

Successful exploitation results in a complete denial of service — the MySQL Server or MySQL Cluster instance will hang or crash in a repeatable fashion, disrupting all database-dependent applications and services. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Because MySQL Cluster is also affected, exploitation could disrupt distributed database environments, potentially impacting multiple nodes simultaneously (Oracle Advisory).

Mitigation and workarounds

Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update, addressing MySQL Server and MySQL Cluster versions 9.7.0–9.7.1. Administrators should apply the Oracle July 2026 CPU patches immediately by following the MySQL patch availability documentation linked from the advisory. As a temporary workaround, restrict network access to the MySQL Server to only trusted, necessary administrative users and monitor for unusual query patterns or repeated connection attempts from privileged accounts. Oracle strongly advises against relying on network-blocking workarounds as a long-term solution (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61109MEDIUM6.5
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoYesJul 21, 2026
CVE-2026-61108MEDIUM6.5
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61144MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_cluster
NoNoJul 21, 2026
CVE-2026-61128MEDIUM4.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoNoJul 21, 2026
CVE-2026-61096LOW2.9
  • MySQL logoMySQL
  • cpe:2.3:a:oracle:mysql_server
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management