CYBERSECURITYTRACKER
TRACKING6,662 stories in this site build1,369 vulnerability news stories in this site build
Permanent story citation

CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7321

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution

CVE-2026-60163 in MySQL Group Replication allows unauthenticated remote attackers to execute arbitrary SQL on destination systems. Oracle initially classified the attack vector as local but reclassified it to adjacent network following discussion, though the full attack surface may be remotely reachable in some configurations.

Why it matters: Database administrators managing MySQL Group Replication deployments must assess exposure to this unauthenticated remote code execution vulnerability and apply patches from Oracle immediately.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary