📊 HiddenMerit Daily · Issue 54
Focus on Database Frontiers, Practical Insights for DBAs July 5, 2026 | 5 Selected Global Breaking News
01|OceanBase CEO Yang Bing: AI Era Brings Important Opportunity to Redefine Foundational Software
On July 2, OceanBase CEO Yang Bing published an opinion article in People’s Daily titled “The AI Era Brings an Important Opportunity to Redefine Foundational Software.” The article points out that as large model capabilities increasingly converge, the focus of AI competition is shifting from “whose model is stronger” to “who can enable AI to truly understand the business.” Databases are being pushed to the core of AI infrastructure, and for the first time, China has the opportunity to evolve from a “follower” of foundational software standards to a “co‑definer.”
Core Judgement: “An AI database is not a simple patch to the previous generation of products, but a reconstruction of the underlying infrastructure.” Yang Bing believes that databases are, for the first time, encountering non‑human users – agents. What agents need is a complete multi‑modal world. AI databases must natively possess three key capabilities: context (precise information supply), scale (supporting tens of millions of agents with independent data spaces), and evolution (a safe environment for trial and error). Over 80% of the world’s unstructured data has, for the first time, become “computable” because of AI. A true AI database must unify multiple data modalities within a single engine, and “lakehouse integration” is the architecture capable of supporting this requirement.
Market Data: According to the latest Gartner forecast, the global DBMS market is expected to reach $161 billion in 2026, growing 18.4% year‑on‑year. Non‑relational DBMS growth is 22.7%, more than double the 10.8% growth rate of relational DBMS. The domestic database replacement rate in the Chinese market has already exceeded 35% and is expected to reach over 70% in 2026. OceanBase has been ranked #1 in market share in China’s financial industry distributed database on‑premises deployment market for three consecutive years.
-
DBA Perspective: Yang Bing’s judgement provides DBAs with a macro framework for understanding industry change. An AI database must unify multiple data modalities within a single engine – the “lakehouse‑integrated” architecture requires DBAs to have the ability to uniformly manage structured, semi‑structured, and unstructured data. Agents becoming the new users of databases means the DBA’s focus will shift from “serving human users” to “serving AI agents,” requiring a redesign of permission governance, audit trails, and resource isolation strategies. The Gartner forecast of a $161 billion market and non‑relational growth double that of relational databases also indicates that DBAs cannot bet solely on relational databases in their skill development.
-
CTO Perspective: Yang Bing’s judgement of moving “from follower to co‑definer” is a key signal of the maturity of China’s foundational software industry. Market data validates the window of opportunity for domestic databases – China has the potential to take the lead in defining new paradigms and standards in the AI database space, rather than simply playing catch‑up.
-
Investor Perspective: OceanBase’s strategic upgrade path from “distributed database replacement” to “AI data infrastructure” is clear. Yang Bing’s judgement, combined with Gartner’s market forecast, provides macro‑level endorsement for the long‑term investment logic in the database sector.
02|CETC Kingware, Hygon, and Kylin Reach Strategic Cooperation: “Chip + OS + Database” Iron Triangle Takes Shape
On June 30, CETC Kingware, Hygon Information, and Kylin Software signed a strategic cooperation agreement in Beijing. The three parties will conduct deep technical integration and innovation around the three core foundations – database, chip, and operating system – jointly building an autonomous and controllable AI integrated full‑stack solution, providing a technical path for the digital and intelligent transformation of key industries such as finance, energy, healthcare, and transportation.
Roles of Each Party:
- CETC Kingware: AI data foundation, with a built‑in native AI vector engine, enabling business queries and semantic hybrid retrieval through a single SQL statement.
- Hygon Information: Underlying compute power support, with a “CPU+DCU” dual‑chip collaborative architecture.
- Kylin Software: Full‑stack scheduling hub, with a Panshi kernel + AI unified scheduling system.
The three parties have already implemented benchmark practices in finance (intelligent risk control), energy (intelligent load scheduling), healthcare (multi‑modal retrieval of electronic medical records), and transportation (track sensor data prediction).
-
DBA Perspective: The strategic cooperation between Kingware, Hygon, and Kylin is a landmark event in the evolution of the Xinchuang ecosystem from “single‑point replacement” to “full‑stack collaboration.” The deep integration of the three core foundations – chip, operating system, and database – means that the DBA’s scope of responsibility in Xinchuang projects will expand from “managing databases” to “evaluating full‑stack compatibility” – requiring an understanding of Hygon CPU compute characteristics, Kylin OS kernel parameter tuning, and their collaborative performance with the Kingware database.
-
CTO Perspective: The deep strategic cooperation among the three core domestic vendors – chip, OS, and database – provides CTOs with a “verified full‑stack solution” for Xinchuang selection. The three parties have already established benchmark cases in finance, energy, healthcare, and transportation, reducing selection risk.
03|Latest Gartner Forecast: Global Database Market at $161 Billion, Non‑Relational Growth Double That of Relational
The latest Gartner forecast for the global database management system (DBMS) market shows that the global DBMS market is expected to reach $161 billion in 2026, growing 18.4% year‑on‑year. This growth rate far exceeds the overall global IT market growth rate, as the database sector experiences unprecedented expansion driven by AI.
Structural Changes:
- Non‑relational DBMS growth has reached 22.7% , more than double the 10.8% growth rate of relational DBMS.
- Among the top five vendors, Oracle’s market share is slowly but steadily declining.
- Cloud dbPaaS continues to capture most of the market增量, while the share of traditional on‑premises databases continues to shrink.
Chinese Market: The domestic database replacement rate has already exceeded 35% and is expected to reach over 70% in 2026. The 2027 deadline for 100% replacement in central SOEs makes 2026 a critical sprint year.
-
DBA Perspective: The data on a $161 billion market and non‑relational growth double that of relational databases provides macro‑level direction for DBAs’ career planning. AI‑driven new data types – vectors, graphs, JSON – are rapidly eroding the share of traditional relational databases; DBAs cannot bet solely on a single technology stack. Cloud dbPaaS continuing to capture market增量 also indicates that DBAs need to accelerate their learning of cloud‑native database operations skills.
-
CTO Perspective: Non‑relational growth double that of relational databases indicates that enterprise data management is shifting from “structured data uniformity” to “multi‑modal data convergence.” When planning data architecture, CTOs should prioritise database platforms with multi‑modal convergence capabilities.
-
Investor Perspective: Oracle’s continued market share decline is a direct signal of the reshaping of the database market landscape. The domestic database replacement rate in China exceeding 35% and expected to reach over 70% in 2026 means domestic database vendors are in a dual window of opportunity driven by both Xinchuang replacement and AI.
04|Dameng Granted New ETL Permission Control Patent, Channel Ecosystem Conference Successfully Held in Nanchang
On July 3, Dameng was granted an invention patent for “A Method and Device for ETL File Permission Control” (authorisation announcement number CN115794820B). The patent enables ETL software to directly control file permissions, significantly improving permission retrieval efficiency by constructing a permission index tree and a hash table.
On the same day, Dameng successfully held the “Dreaming New Chapter, Gathering for Win‑Win” 2026 Channel Ecosystem Conference in Nanchang. Dameng showcased multiple core products, including DM9, the next‑generation database all‑in‑one machine, Qiyun Database V4.0, and the graph database GDMBASE V4.0, covering general‑purpose relational databases, software‑hardware integration, cloud‑native, and graph computing scenarios.
Product Highlights:
-
DM9: Centralised and distributed integrated architecture with over 450 feature upgrades, already running stably in core systems across multiple industries in Jiangxi.
-
Next‑Gen All‑in‑One: IOPS starting at 12 million, I/O latency reduced from 400μs to 80μs.
-
Dameng Graph Database V4.0: Graph‑native + vector integrated architecture, HyperRAG global retrieval, supporting ultra‑large‑scale graph data exceeding 100 billion edges.
-
DBA Perspective: Dameng’s ETL permission control patent enables direct control of ETL file permissions, improving retrieval efficiency through a permission index tree and hash table. For DBAs, this means more refined and efficient permission management in ETL pipelines. The holding of Dameng’s channel ecosystem conference in Nanchang, and the stable operation of DM9 in core systems across multiple industries in Jiangxi, indicate that Dameng is accelerating its presence in regional markets. Demand for domestic database positions in regional financial institutions and government‑enterprise projects is being释放.
-
CTO Perspective: Dameng’s full‑stack product matrix (DM9, all‑in‑one, Qiyun V4.0, graph database V4.0) covers relational, cloud‑native, graph computing, and other diverse scenarios, providing CTOs with a one‑stop selection option from transactions to analytics to AI.
-
Investor Perspective: Dameng’s 2025 net profit of RMB 515 million and 92.55% software authorisation revenue ratio provide strong valuation support for it in the domestic database track. The continued expansion of its channel ecosystem and the refinement of its full‑stack product capabilities are key drivers for Dameng to increase its market share.
05|Weekly Security Vulnerabilities Focus: Weaviate Privilege Bypass, Chamilo LMS SQL Injection, AlmaLinux MySQL Security Update
Multiple database‑related security vulnerabilities were disclosed this week:
Weaviate Privilege Bypass (CVE-2026-59093) : Affects Weaviate versions before 1.38.0. The vulnerability stems from a lack of verification during RBAC role assignment that the principal performing the assignment holds the permissions granted by the assigned role. This allows users with delegated assign_and_revoke_users or assign_and_revoke_groups permissions to assign built‑in admin roles or high‑privilege custom roles to themselves or other users, gaining full control of the database.
Chamilo LMS SQL Injection (SB2026070347) : Affects the /main/inc/ajax/model.ajax.php endpoint of Chamilo LMS. Due to insufficient filtering of user input, a remote administrator can send specially crafted requests to execute arbitrary SQL commands, achieving read, delete, modify, and full control over the application database.
AlmaLinux MySQL Security Update (ALSA-2026:25052) : AlmaLinux released a MySQL 8.4 security update fixing multiple vulnerabilities, including CVE-2026-22004 (InnoDB), CVE-2026-22015 (Information Schema privilege escalation), CVE-2026-22005 (Optimizer), and others. Affected versions include MySQL 8.4.8 and below. Users are advised to upgrade to the fixed versions.
-
DBA Perspective: The Weaviate privilege bypass vulnerability allows low‑privilege users to assign admin roles to themselves. This once again reminds DBAs that the security maturity of emerging components such as AI databases and vector databases remains concerning. DBAs using Weaviate should upgrade immediately to version 1.38.0 or higher and review RBAC role assignment records. The Chamilo LMS SQL injection vulnerability warns that SQL injection at the enterprise application layer is still frequent. DBAs should work with security teams to conduct specialised audits of application‑layer components with “database read/write privileges.” The AlmaLinux MySQL security update covers multiple CVEs, including CVE-2026-22015 (Information Schema privilege escalation). DBAs running MySQL 8.4 should evaluate patch priority as soon as possible.
-
CTO Perspective: The occurrence pattern of the Weaviate vulnerability (lack of verification in RBAC role assignment) is closely related to the rapid iteration characteristics of vector databases. This reminds CTOs that when introducing new database components, permission model auditing should be included in the security baseline.
-
Investor Perspective: The continued exposure of security vulnerabilities in AI databases and vector databases will drive enterprise customers to increase procurement of AI infrastructure security auditing and vulnerability scanning services.
📚 SQL Little Knowledge Point
This Issue’s Knowledge Point: What is “Lakehouse Integration”?
“Lakehouse Integration” is a new database architecture paradigm proposed by OceanBase for the AI era – unifying the openness and massive storage capabilities of data lakes, the transaction processing and analytical capabilities of databases, and multi‑modal data processing capabilities into a single strongly‑consistent data foundation.
Why is Lakehouse Integration Needed?
Data in the AI era presents three major changes:
- The data consumer has changed: AI agents are becoming the new users of databases. Gartner predicts that by 2028, approximately one‑third of enterprise software interactions will be completed by agents.
- The form of data has changed: Over 80% of global data is unstructured (text, images, audio, video). AI has made them “computable” for the first time.
- The value of data has changed: Unstructured data has evolved from “scraps” for enterprises to core assets.
Under traditional architecture, enterprises need to maintain multiple systems – transaction DB + data warehouse + vector DB + data lake – leading to data fragmentation, complex operations, and difficult‑to‑ensure consistency. Lakehouse integration unifies the management of structured, semi‑structured, and unstructured data within a single engine, enabling AI agents to obtain complete business context in one go.
OceanBase Lakehouse Integration Validated Capability: Already validated in scenarios such as Ant Afu and Lingguang. Lingguang has already hosted 30 million “flash applications” , validating the feasibility of the lakehouse‑integrated architecture in scenarios with tens of millions of agents.
Significance for DBAs: Lakehouse integration means DBAs will be freed from the heavy work of “maintaining multiple systems,” but it also requires DBAs to develop new skills in multi‑modal data modelling, vector index maintenance, and mixed‑load tuning.
HiddenMerit Team Production Slogan: 绩优隐于内,金石启新程 | Hidden deep. Merit bold. Forge ahead.