{
  "cve": "CVE-2026-60179",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[9.7.0,9.7.1]"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "manual",
          "scores": [
            {
              "score": 100.0,
              "source": "manual"
            }
          ]
        },
        "product": "mysql_connectors",
        "vendor": "oracle"
      }
    ],
    "created": "2026-07-23T21:12:17.960143+00:00",
    "updated": "2026-08-04T05:00:05.029777+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$mysql_connectors"
    ]
  },
  "epss": {
    "score": 0.0034
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:mysql_connector\\/c\\+\\+:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-07-21T21:33:33.247000+00:00",
    "description": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.4,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/60xxx/CVE-2026-60179.json",
    "references": [
      "https://www.oracle.com/security-alerts/cpujul2026.html"
    ],
    "title": null,
    "updated": "2026-07-25T03:56:14.065000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$mysql_connector\\/c\\+\\+"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:oracle:mysql_connector\\/c\\+\\+:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-07-21T22:17:18.847000+00:00",
    "description": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.4,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-60179.json",
    "references": [
      "https://www.oracle.com/security-alerts/cpujul2026.html"
    ],
    "title": null,
    "updated": "2026-08-06T18:16:32.740000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$mysql_connector\\/c\\+\\+"
    ],
    "weaknesses": [
      "CWE-284"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-07-21T21:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$mysql_connector\\/c\\+\\+"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:mysql_connector\\/c\\+\\+:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$mysql_connector\\/c\\+\\+"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cpujul2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 7.4,
                  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "e61030ca-4572-4aff-8a3e-d91e09d58c2b"
      },
      {
        "created": "2026-07-23T21:45:00+00:00",
        "data": [
          {
            "details": [
              "oracle$PRODUCT$mysql_connectors"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "oracle$PRODUCT$mysql_connectors"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "919508fa-202d-4797-a7d0-1aff6f9cddf4"
      },
      {
        "created": "2026-07-24T02:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Unauthenticated Remote Data Access via MySQL Connector/C++ Vulnerability",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-285"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "d518d228-42bc-470e-9714-86fdb8715e2d"
      },
      {
        "created": "2026-07-27T14:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Unauthenticated Remote Data Access via MySQL Connector/C++ Vulnerability"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-285"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "0f0497bd-33ef-45f5-aa39-277046dcb776"
      },
      {
        "created": "2026-07-30T16:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Authentication Bypass in Oracle MySQL Connector/C++ Allows Unauthorized Data Modification",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "c5481740-b921-4278-9b89-4ed5729760f0"
      },
      {
        "created": "2026-08-04T05:15:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Authentication Bypass in Oracle MySQL Connector/C++ Allows Unauthorized Data Modification"
            },
            "type": "title"
          }
        ],
        "id": "60a7b663-7842-46d8-9913-43e986f019eb"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:mysql_connector\\/c\\+\\+:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-07-21T21:33:33.247000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 7.4,
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.0034
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cpujul2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": null,
      "provider": null
    },
    "updated": {
      "data": "2026-08-04T05:00:05.029777+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$mysql_connector\\/c\\+\\+",
        "oracle$PRODUCT$mysql_connectors"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-284"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-07-21T21:33:33.247000+00:00",
    "description": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-07-23T16:16:08.184000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/60xxx/CVE-2026-60179.json",
    "weaknesses": [
      "CWE-284"
    ]
  }
}