ZeroHour
oss-securitypublished ()ingested 1

CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution

AI summary · glm-5.3

Oracle reclassified MySQL Group Replication flaw CVE-2026-60163 from Local to Adjacent Network; researcher says it enables unauthenticated remote arbitrary SQL execution.

CVE-2026-60163 in MySQL Group Replication permits an unauthenticated remote attacker to execute arbitrary SQL on the destination server. Following discussion after the July disclosure, Oracle revised the CVSS attack vector rating from 'Local' to 'Adjacent Network'. The researcher posting to oss-security clarifies that, in the extreme, the attack surface is reachable fully remotely.

  • Unauthenticated attacker can execute arbitrary SQL on target
  • Oracle changed attack vector rating from Local to Adjacent Network
  • Researcher argues the flaw can be reachable fully remotely
  • Disclosed in July 2026, shared belatedly in September

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60163
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component:

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

NVD description · AI analysis pending
8.4<1%
  • oracle mysql server
  • oracle mysql cluster
Full article

Posted by manizada on Sep 14 Hi folks, Sharing (belatedly) the July disclosure of the MySQL CVE-2026-60163 + an update on its reclassification. The vulnerability permits an unauthenticated remote attacker to execute arbitrary SQL on the destination. Following discussion, Oracle revised the attack vector rating from 'Local' to 'Adjacent Network'. Posting to clarify this further; the attack surface -- in the extreme -- is reachable fully remotely (not...

This source does not provide full text. Read it at seclists.org.