Skip to content

CVE-2026-46861: Privilege Escalation and Cluster Takeover in MySQL NDB Operator

HERMES

HERMES THREAT SCORE & OPERATIONAL EXPOSURE

Target: MySQL NDB Cluster (Cluster: NDB Operator) β€” Oracle MySQL Enterprise & Community Ecosystem
Confidence: 95%
92 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 19 / 20
Threat Activity 17 / 20
Weaponization 18 / 20
Exposure 18 / 20
Prevalence 19 / 20
Impact 20 / 20
Exploit Maturity 16 / 20
Attack Chain Potential 19 / 20
βš–οΈ Divergence & Operational Rationale

Hermes assigns a threat score of 92 (CRITICAL). In cloud-native Kubernetes environments, compromising the NDB Operator provides a direct pathway to mutate cluster CRDs, exfiltrate persistent storage volumes, and compromise neighboring pods across the Kubernetes tenant.

HASS

HASS INFRASTRUCTURE & AGENTIC IMPACT POSTURE

Target: Kubernetes Control Plane, Operator Controllers & Cloud Storage
Confidence: 92%
85 / 100
CRITICAL

Measures specific systemic risk arising from autonomy, tool authority, and cascading execution.

Dimension Breakdown
Autonomy 14 / 20
Tool Access 18 / 20
Privilege 17 / 15
Persistence 14 / 15
External Impact 16 / 15
Propagation 17 / 15
βš–οΈ Divergence & Operational Rationale

Modern automated database deployment pipelines, agentic query tooling, and Kubernetes operators rely on reliable boundaries. Compromising MySQL NDB Cluster (Cluster: NDB Operator) allows adversaries to pierce compartmentalization boundaries and expand footholds across adjacent infrastructure.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-46861: Privilege Escalation and Cluster Takeover in MySQL NDB OperatorVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTOracle MySQL NDB Cluster
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Oracle MySQL NDB Cluster documented in Hermes dossier.”

Supporting Verified Evidence:

MySQL NDB Cluster (Cluster: NDB Operator) plays a central role within the Oracle MySQL ecosystem. Flaws in this layer expose both database assets and interconnecting applications.

ParameterTechnical SpecificationOperational Context
CVE IdentifierCVE-2026-46861Oracle CPU Record / NVD Reference
Component NameMySQL NDB Cluster (Cluster: NDB Operator)Oracle MySQL Ecosystem
Vulnerability ClassKubernetes RBAC Bypass / Cluster CompromiseCWE-284 (Improper Access Control)
Network VectorTCP 8080 / 9443 (Webhook & Operator HTTP API)Low Privileged Network Access
Scope ImpactScope Change (S:C) β€” Host/Cluster EscapingImpact across trust boundaries
Affected VersionsMySQL NDB Cluster 8.0.11–8.0.46, 8.4.0–8.4.9, 9.0.0–9.7.0Prior releases lacking patch validation
Fixed Releases8.0.47, 8.4.10, 9.7.1Available in official Oracle distribution

Flaw Mechanism in MySQL NDB Cluster (Cluster: NDB Operator)

Section titled β€œFlaw Mechanism in MySQL NDB Cluster (Cluster: NDB Operator)”

The vulnerability originates from insufficient input sanitization, improper access control, or incorrect privilege delegation within MySQL NDB Cluster (Cluster: NDB Operator).

+-------------------------------------------------------------------------+
| ATTACK INGRESS |
| Attacker / Rogue Client ==[ AV:N ]==> MySQL NDB Cluster (Cluster: NDB Operator) |
+-------------------------------------------------------------------------+
|
v
+-------------------------------------------------------------------------+
| VULNERABILITY EXECUTION BOUNDARY |
| - Parsing & Verification Defect: CWE-284 (Improper Access Control) |
| - Security Boundary Failure: Breaks out into Host OS / Kubernetes |
+-------------------------------------------------------------------------+
|
v
+-------------------------------------------------------------------------+
| IMPACTED ASSETS |
| - Confidentiality: Full Host / DB Read |
| - Integrity: Arbitrary State Manipulation |
| - Availability: Limited |
+-------------------------------------------------------------------------+

When receiving requests over TCP 8080 / 9443 (Webhook & Operator HTTP API), the component fails to enforce strict boundary restrictions. An attacker capitalizing on this logic gap can manipulate execution state, invoke privileged RPC endpoints, or crash daemon routines.


sequenceDiagram
autonumber
actor Attacker as Attacker / Compromised Client
participant Target as MySQL NDB Cluster (Cluster: NDB Operator)
participant Backend as Core Database / Host Runtime
Attacker->>Target: Transmit crafted payload over TCP 8080 / 9443 (Webhook & Operator HTTP API)
Note over Target: Trigger logic bug: CWE-284
Target->>Backend: Execute unauthorized action / Unvalidated RPC
Note over Backend: Scope Change triggered: Host breakout
Backend-->>Attacker: Administrative access / Intercepted credentials / Denial of Service

title: Suspicious Activity Related to CVE-2026-46861 in MySQL NDB Cluster (Cluster: NDB Operator)
id: cve-2026-46861-detection-sigma
status: experimental
description: Detects suspicious process lineage or abnormal command execution related to CVE-2026-46861.
references:
- https://www.oracle.com/security-alerts/
author: Hermes Codex Cyber Intelligence
date: 2026-09-15
tags:
- attack.initial_access
- attack.execution
- attack.t1190
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- 'ndb-operator'
selection_child:
Image|endswith:
- 'kubectl'
condition: selection_parent and selection_child
level: high

  1. Apply Official Oracle Vendor Patches: Upgrade MySQL NDB Cluster (Cluster: NDB Operator) to release 8.0.47, 8.4.10, 9.7.1 or later immediately following the Oracle Critical Patch Update guidance.

  2. Enforce Network Segmentation & Access Control: Restrict access to port TCP 8080 / 9443 (Webhook & Operator HTTP API). Under no circumstances should management, routing, or internal shell RPC endpoints be exposed to the public Internet or untrusted subnets.

  3. Audit Privileges and Role Assignments: Review database user grants (SUPER, REPLICATION SLAVE, BACKUP_ADMIN). Ensure the principle of least privilege is rigorously applied across application and operator service accounts.

  4. Rotate Infrastructure Credentials: If compromise or unauthorized access is suspected, immediately rotate database administrative passwords, TLS certificates, and Kubernetes service account tokens.