
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61128 is a Denial of Service vulnerability in the Server: Optimizer component of Oracle MySQL Server and MySQL Cluster, affecting versions 9.7.0 through 9.7.1. It was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. The vulnerability allows a high-privileged attacker with network access to cause the database server to hang or crash repeatedly, resulting in a complete denial of service. It carries a CVSS v3.1 base score of 4.9 (Medium) (Oracle Advisory).
The vulnerability resides in the Server: Optimizer component of MySQL Server and MySQL Cluster, classified as an availability-impacting flaw (CWE category consistent with improper input handling leading to server crash). An attacker with high privileges and network access can send crafted queries or optimizer-triggering inputs via multiple supported protocols (e.g., MySQL protocol, TCP/IP) that cause the server to hang or crash in a frequently repeatable manner. No authentication bypass is involved — the attacker must already hold high-privileged database credentials. No public technical write-up or proof-of-concept code has been identified at this time (Oracle Advisory).
Successful exploitation results in a complete denial of service — the MySQL Server or MySQL Cluster instance will hang or crash in a repeatable fashion, disrupting all database-dependent applications and services. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Because MySQL Cluster is also affected, exploitation could disrupt distributed database environments, potentially impacting multiple nodes simultaneously (Oracle Advisory).
Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update, addressing MySQL Server and MySQL Cluster versions 9.7.0–9.7.1. Administrators should apply the Oracle July 2026 CPU patches immediately by following the MySQL patch availability documentation linked from the advisory. As a temporary workaround, restrict network access to the MySQL Server to only trusted, necessary administrative users and monitor for unusual query patterns or repeated connection attempts from privileged accounts. Oracle strongly advises against relying on network-blocking workarounds as a long-term solution (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."