Download
Security Advisory; NCSC-2026-0262 [1.0.0]
- Security Advisory
- NCSC-2026-0262 [1.0.0]
- Publicatie
- 22-07-2026 17:25 (Europe/Amsterdam)
- Prioriteit
- Normaal
- Betreft
- Kwetsbaarheden verholpen in Oracle MySQL Server en MySQL Cluster
Kenmerken
- Improper Resource Shutdown or Release
Omschrijving
Oracle heeft meerdere kwetsbaarheden verholpen in Oracle MySQL Server en MySQL Cluster.
De kwetsbaarheden betreffen verschillende versies van Oracle MySQL Server en MySQL Cluster. Een aantal kwetsbaarheden stelt een aanvaller met hoge privileges en netwerktoegang in staat om een denial-of-service (DoS) te veroorzaken, waarbij de server kan hangen of crashen, wat de beschikbaarheid van de database beïnvloedt. Sommige DoS-kwetsbaarheden kunnen ook door laaggeprivilegieerde gebruikers worden misbruikt.
Daarnaast zijn er kwetsbaarheden in de Group Replication Plugin en de NDB Operator component die DoS of ongeautoriseerde toegang tot data mogelijk maken.
Verder zijn er kwetsbaarheden die een aanvaller met hoge privileges en netwerktoegang in staat stellen om volledige controle over de server te verkrijgen, wat impact heeft op vertrouwelijkheid, integriteit en beschikbaarheid.
Ook zijn er kwetsbaarheden in Oracle MySQL Connectors (Connector/C++, Connector/Net, Connector/J) die ongeauthenticeerde of laaggeprivilegieerde aanvallers met netwerktoegang toestaan om data te manipuleren, toegang te verkrijgen tot gevoelige informatie of een denial-of-service te veroorzaken. Sommige kwetsbaarheden vereisen gebruikersinteractie of lokale toegang.
De CVSS 3.1 scores variëren van laag (2.2) tot hoog (8.5), afhankelijk van het type kwetsbaarheid en de impact op de systemen. De kwetsbaarheden zijn specifiek voor Oracle MySQL Server, MySQL Cluster en de MySQL Connectors, en zijn exploiteerbaar via netwerktoegang, soms met aanvullende vereisten zoals infrastructuurtoegang, gebruikersinteractie of lokale toegang.
Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden in Oracle MySQL Server, MySQL Cluster en MySQL Connectors te verhelpen. Zie bijgevoegde referenties voor meer informatie.
Referenties
CVE's
- CVE-2026-46936 - CVSS (v3) 4.4
- CVE-2026-47008 - CVSS (v3) 4.9
- CVE-2026-47012 - CVSS (v3) 4.4
- CVE-2026-47023 - CVSS (v3) 4.9
- CVE-2026-47052 - CVSS (v4) 6.9
- CVE-2026-47064 - CVSS (v3) 6.5
- CVE-2026-60145 - CVSS (v3) 4.9
- CVE-2026-60163 - CVSS (v3) 8.4
- CVE-2026-60171 - CVSS (v3) 4.9
- CVE-2026-60174 - CVSS (v3) 6.5
- CVE-2026-60177 - CVSS (v3) 4.4
- CVE-2026-60178 - CVSS (v3) 6.6
- CVE-2026-60179 - CVSS (v3) 7.4
- CVE-2026-60180 - CVSS (v3) 7.5
- CVE-2026-60181 - CVSS (v3) 6.7
- CVE-2026-60182 - CVSS (v3) 4.4
- CVE-2026-60183 - CVSS (v3) 6.4
- CVE-2026-60184 - CVSS (v3) 4.4
- CVE-2026-60185 - CVSS (v3) 4.4
- CVE-2026-60186 - CVSS (v3) 4.4
- CVE-2026-60187 - CVSS (v3) 4.4
- CVE-2026-60188 - CVSS (v3) 4.4
- CVE-2026-60189 - CVSS (v3) 4.4
- CVE-2026-60190 - CVSS (v3) 2.2
- CVE-2026-60191 - CVSS (v3) 4.1
- CVE-2026-60192 - CVSS (v3) 8.1
- CVE-2026-60193 - CVSS (v3) 8.5
- CVE-2026-60194 - CVSS (v3) 4.9
- CVE-2026-60195 - CVSS (v3) 4.9
- CVE-2026-60311 - CVSS (v3) 6.5
- CVE-2026-60314 - CVSS (v3) 7.5
- CVE-2026-60315 - CVSS (v3) 8.2
- CVE-2026-60316 - CVSS (v3) 7.2
- CVE-2026-60317 - CVSS (v3) 7.4
- CVE-2026-60324 - CVSS (v3) 6.5
- CVE-2026-60331 - CVSS (v3) 6.4
- CVE-2026-60332 - CVSS (v3) 6.4
- CVE-2026-60569 - CVSS (v3) 5.1
- CVE-2026-60585 - CVSS (v3) 6.6
- CVE-2026-60586 - CVSS (v3) 7.7
- CVE-2026-60623 - CVSS (v3) 7.1
- CVE-2026-60624 - CVSS (v3) 6.5
- CVE-2026-60718 - CVSS (v3) 6.5
- CVE-2026-60725 - CVSS (v3) 7.4
- CVE-2026-60747 - CVSS (v3) 6.2
- CVE-2026-61081 - CVSS (v3) 2.7
- CVE-2026-61082 - CVSS (v3) 6.5
- CVE-2026-61093 - CVSS (v3) 6.5
- CVE-2026-61094 - CVSS (v3) 7.2
- CVE-2026-61096 - CVSS (v3) 2.9
- CVE-2026-61108 - CVSS (v3) 6.5
- CVE-2026-61109 - CVSS (v3) 6.5
- CVE-2026-61128 - CVSS (v3) 4.9
- CVE-2026-61144 - CVSS (v3) 4.9
Producten
Oracle
Disclaimer
The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.