Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Project Subscriptions

Vendors Products
Mysql Connector/j Subscribe
Mysql Connector\/j Subscribe
Mysql Connectors Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Enables Unauthorized Data Access in MySQL Connector/J
Weaknesses CWE-284

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Enables Unauthorized Data Access in MySQL Connector/J
Weaknesses CWE-284

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle MySQL Connector/J Leading to Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle MySQL Connector/J Leading to Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Wed, 22 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle mysql Connector/j
Oracle mysql Connectors
Vendors & Products Oracle mysql Connector/j
Oracle mysql Connectors

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle mysql Connector\/j
CPEs cpe:2.3:a:oracle:mysql_connector\/j:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Connector\/j
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T18:19:01.584Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60586

cve-icon Vulnrichment

Updated: 2026-07-29T18:18:58.775Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses