---
title: "CVE-2026-60331\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-60331?format=md
keywords: index, follow
---

# CVE-2026-60331

Publication date 21 July 2026

Last updated 31 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.4 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2026-60331?format=md#impact-score)

Toggle side navigation

## Description

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL
(component: Server: Replication). Supported versions that are affected are
MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47,
8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows
high privileged attacker with logon to the infrastructure where MySQL
Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.
Successful attacks of this vulnerability can result in takeover of MySQL
Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity
and Availability impacts). CVSS Vector:
(CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-60331?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mysql-5.5 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Ignored see notes |
| mysql-5.7 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Ignored see notes |
| 16.04 LTS xenial | Ignored see notes |
| mysql-8.0 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Fixed 8.0.46-0ubuntu0.24.04.4 |
| 22.04 LTS jammy | Fixed 8.0.46-0ubuntu0.22.04.4 |
| 20.04 LTS focal | Needs evaluation |
| mysql-8.4 | 26.04 LTS resolute | Fixed 8.4.11-0ubuntu0.26.04.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| mariadb | 26.04 LTS resolute | Needs evaluation |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Not in release |
| mariadb-10.0 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |
| mariadb-10.1 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| mariadb-10.3 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Ignored no more upstream support |
| mariadb-10.6 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Needs evaluation |
| percona-xtradb-cluster-5.6 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |
| percona-server-5.6 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [iconstantin](https://launchpad.net/~iconstantin)

since mysql versions 5.7 and earlier are no longer supported
upstream, we are unable to update them to address security
issues,
marking as ignored.
mariadb 5.5, 10.0, 10.1, and 10.3 are end of life and no
longer supported upstream - marking as ignored.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.4 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Privileges required | High |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.4 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-60331)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-60331)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-60331)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-60331)

### Related Ubuntu Security Notices (USN)

+ [USN-8700-1](https://usn.ubuntu.com/USN-8700-1)
+ MySQL vulnerabilities
+ 31 August 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-60331>
* <https://www.oracle.com/security-alerts/cpujul2026.html>
