HiddenMerit Daily · Issue 57

# 📊 HiddenMerit Daily · Issue 57

> Focus on Database Frontiers, Practical Insights for DBAs

> July 17, 2026 | 5 Selected Global Breaking News

## 01|CAICT Releases “Database Development Research Report (2026)”: China Market to Reach RMB 98 Billion by 2028, AI‑Native Becomes the Main Theme

On July 9, at the 2026 Trustworthy Database Development Conference, the China Academy of Information and Communications Technology (CAICT) officially released the “Database Development Research Report (2026),” comprehensively revealing the latest landscape and evolution directions of the global and Chinese database markets.

Key Data:

- Global Market: The global database market reached $131.6 billion in 2025 (approximately RMB 894.09 billion).

- Chinese Market: The Chinese database market reached $9.49 billion in 2025 (approximately RMB 64.48 billion), accounting for 7.2% of the global market. By 2028, the total Chinese database market is expected to reach RMB 97.974 billion, with a compound annual growth rate of 13.06% .

- Industry Landscape: There are 394 database product providers globally, with China and the US leading in vendor count. The number of global open‑source and closed‑source products is roughly balanced. Commercial databases account for over 70% in China, while the proportion of open‑source databases is increasing. After rapid growth from 2022 to 2024, the number of database products significantly declined in 2025, with a clear head‑concentration effect. In 2026, the product count rebounded to 182, with AI‑oriented database products emerging at an accelerated pace.

CAICT Interpretation: Wei Liang, Vice President of CAICT, noted that artificial intelligence is reshaping industries at an unprecedented speed. As the critical foundation for massive data storage, computing, and intelligent processing, databases are undergoing a profound paradigm shift. In 2026, database technology is accelerating its evolution toward the AI‑native direction, and the global database industry is entering a new phase of landscape restructuring. At the application level, key industries are gradually adopting a pragmatic approach of tiered deployment and differentiated selection. Databases are evolving from underlying support systems into core engines enabling intelligent decision‑making and business innovation.

Key Conference Highlights:

- Three Sub‑Forums: AI and Database Integration, Telecommunications Industry, and Financial Industry were held concurrently.

- Initiative Launch: OceanBase, together with CAICT and multiple leading ISVs, launched the Critical Industry “AI Database” Initiative.

- DBA Perspective: The forecast of a nearly RMB 98 billion market by 2028 provides macro‑level confidence for DBAs’ career development. The report’s clear “AI‑native evolution” direction and head‑concentration trend mean that domestic database replacement in critical industries such as finance, telecommunications, and government has moved from “peripheral pilots” to the “deep water zone.” DBAs’ skill sets must upgrade from “basic domestic database operations” to “multi‑modal data processing and mixed‑load tuning under AI‑native architectures.”

- CTO Perspective: The CAICT report provides CTOs with quantifiable industry benchmarks for Xinchuang selection. The “head‑concentration” signal means the selection scope is converging toward leading vendors. When evaluating technology roadmaps, CTOs should prioritise head products that occupy core positions in the industry landscape.

- Investor Perspective: The nearly RMB 98 billion market size by 2028, combined with a 13.06% CAGR, provides macro‑level endorsement for the long‑term investment logic in the database sector. The establishment of the AI‑native direction and the trend toward head‑concentration mean that leading vendors with technical accumulation in multi‑modal convergence and AI‑native capabilities will command higher valuation premiums.

## 02|CAICT Industry Landscape (2026): OceanBase Achieves “One Vertical, One Horizontal” Breakthrough, Kingware Covers Six Industries

On July 9, CAICT officially released the “China Database Industry Landscape (2026)” at the Trustworthy Database Development Conference. As a key reference for mapping China’s database industry landscape, the landscape has become an authoritative industry benchmark since its first release in 2025.

OceanBase’s Key Breakthroughs:

- Vertical Leader Expansion: In addition to finance and telecommunications, “Government” has been added as a new leader category for the first time, achieving full coverage of the three core industries: finance, telecommunications, and government.

- Horizontal Technology Expansion: A “Vector Database” category has been newly added to the technology section. OceanBase’s “Lakehouse‑Integrated” AI database capability has been officially included, marking authoritative recognition of its AI‑oriented technology roadmap.

OceanBase Launches Initiative: At the conference, OceanBase, together with CAICT and Shenzhou Information, Neusoft Group, Hundsun Technologies, and Huaxin Yongdao, officially launched the Critical Industry “AI Database” Initiative, focusing on two directions: first, critical business workload – driving domestic databases from “usable” to “good‑to‑use”; second, accelerating AI innovation – using the lakehouse‑integrated AI database as a foundation to enable AI applications to be more accurate, efficient, and secure in critical industries.

CETC Kingware: CETC Kingware appeared across the board, ranking as a leader in six industries: government, telecommunications, energy, transportation, healthcare, and manufacturing. Both its converged database and intelligent database were selected as “Frontier Database Products.” Additionally, Kingware and CAICT jointly initiated the development of the “Intelligent Database Technology Research Report,” advancing industry research from “architectural convergence” to “AI‑deep empowerment.”

- DBA Perspective: CAICT’s industry landscape adding “Government” to OceanBase’s leader categories validates the large‑scale maturity of domestic distributed databases in digital government scenarios. The addition of the “Vector Database” category means vector retrieval capability has become a core database competency – DBAs must accelerate their learning of vector index maintenance, multi‑modal data modelling, and mixed‑load tuning. Kingware’s coverage of six industries means DBAs have a wider range of skill application scenarios in cross‑industry Xinchuang projects.

- CTO Perspective: The authoritative CAICT landscape provides CTOs with a “selection map.” The initiative launched by OceanBase, CAICT, and multiple leading ISVs provides a collaborative ecosystem path for full‑stack domestic upgrades and AI application deployment in critical industries. Kingware being the first to pass the authoritative “Converged Database” test provides a standardised implementation model for industry architecture upgrades.

- Investor Perspective: OceanBase’s “one vertical, one horizontal” breakthrough in the industry landscape provides authoritative endorsement for its valuation logic upgrade from “distributed database replacement” to “AI data infrastructure.” Leading vendors such as Kingware and Dameng continuing to occupy core positions in the landscape validates the industry trend of head‑concentration in the domestic database sector.

## 03|Critical Industry “AI Database” Initiative Launched: Lakehouse Integration Becomes New Paradigm for Government and Enterprise AI Implementation

On July 9, at the 2026 Trustworthy Database Development Conference, OceanBase, together with CAICT and Shenzhou Information, Neusoft Group, Hundsun Technologies, and Huaxin Yongdao, officially launched the Critical Industry “AI Database” Initiative.

Core Directions of the Initiative:

- Critical Business Workload: Jointly drive domestic databases from “usable” to “good‑to‑use,” accelerating full‑stack domestic upgrades in critical industries.

- Accelerating AI Innovation: Using the lakehouse‑integrated AI database as a foundation, enable AI applications to be more accurate, efficient, and secure in critical industries, accelerating the emergence of high‑value AI applications in national livelihood sectors.

Technical Foundation: The technical core of the initiative is OceanBase’s “Lakehouse‑Integrated” AI database, which unifies the openness and massive storage capabilities of data lakes, the transaction processing and analytical capabilities of databases, and multi‑modal data processing capabilities into a single strongly‑consistent data foundation, enabling agents to obtain complete business context in one go. Compared to traditional multi‑system solutions, TCO can be reduced by approximately 30%‑50%. This capability has been validated in scenarios such as Ant Afu and Lingguang, where Lingguang has generated tens of millions of “flash applications,” validating the feasibility of the lakehouse‑integrated architecture in scenarios with tens of millions of agents.

OceanBase CEO Yang Bing stated in a People’s Daily opinion piece: “We have the opportunity to move from ‘followers’ to ‘co‑definers,’ participating in the formation of the AI database paradigm. This is both China’s opportunity and OceanBase’s opportunity.”

- DBA Perspective: The launch of the initiative means the “lakehouse‑integrated” architecture is moving from concept to large‑scale government and enterprise implementation. DBAs need to focus not on replacing a single technology, but on the ability to uniformly manage structured, unstructured, and vector data within a single engine. The 30%‑50% TCO reduction also provides a quantitative basis for DBAs’ cost arguments in technology selection.

- CTO Perspective: The initiative brings together CAICT’s industry research capabilities and leading ISVs’ industry implementation experience, forming a complete closed loop from technical standards to industry practice. OceanBase’s lakehouse‑integrated architecture has been validated in scenarios with tens of millions of agents, reducing risk for CTOs in AI data infrastructure selection.

## 04|GBASE Expands into AI‑Native Databases: GBase 8c Released, Xinchuang Replacement Enters the Second Half

Recently, GBASE held its 2026 Technology Cloud Share Conference in Tianjin. A basic consensus emerged: After Xinchuang (XC) replacement, the next destination is AI. XC replacement is a competition in the existing market, while AI represents a much larger incremental market.

GBase 8c AI‑Native Database: Positioned as a next‑generation AI‑native database, with core capabilities including:

- Multi‑Modal and Multi‑Form: Supports row storage, column storage, and hybrid row‑column storage; supports primary‑standby, distributed, and storage‑compute separation deployments.

- Native Vector Storage and Fused Retrieval: Built‑in HNSW, IVF, PQ, and other quantised indexes; supports hybrid retrieval combining vector similarity, scalar filtering, and full‑text search.

- Data Branching: Supports second‑level branch creation and fast rollback, providing isolated trial‑and‑error environments for AI agents.

- LTAP Lakehouse Integration: In coordination with GBase 8a, achieves real‑time data mirroring, eliminating cumbersome ETL processes.

GBase 8a DataAgent Intelligent Data Analytics Platform: Enables business users to perform self‑service data analytics and business insights through natural language. The architecture includes a lakehouse‑integrated data foundation, an ontology‑based semantic layer, natural language querying, and full‑chain intelligent operations.

- DBA Perspective: GBase 8c’s data branching capability – second‑level creation, fast rollback – allows DBAs to provide independent, isolated environments for each AI agent or AI task, fundamentally changing development and testing workflows. LTAP lakehouse integration eliminates ETL processes, meaning DBAs will be freed from tedious data movement tasks and shift their focus to data freshness and cross‑system consistency.

- CTO Perspective: GBASE’s judgement that “after XC replacement, the next destination is AI” is highly consistent with the CAICT report’s conclusion of “evolution toward the AI‑native direction.” GBase 8c’s multi‑modal and multi‑form capabilities provide CTOs with flexible deployment options across different scenarios (high‑concurrency transactions, real‑time analytics, AI retrieval).

- Investor Perspective: XC replacement represents the first half of the domestic database industry; the AI wave represents the second half, where competition is on equal footing. Having established a foothold in the XC market with its full‑stack products passing security and reliability assessments, GBASE is now actively positioning itself in the AI incremental market. The AI‑native capabilities of GBase 8c are worth continued attention.

## 05|Weekly Security Vulnerabilities Focus: TDengine Stack Buffer Overflow (CVE-2026-62349), FortiWeb SQL Injection

Multiple database‑related security vulnerabilities were disclosed this week:

TDengine Stack Buffer Overflow (CVE-2026-62349, CVSS 8.3) : Affects TDengine versions 3.4.1.6 and earlier. The trimString() function, when handling escape sequences in SQL strings (e.g., \% , \_ , \x), only checks for a single‑byte space, causing a single‑byte out‑of‑bounds write to the stack buffer tmpTokenBuf, which can lead to denial of service (DoS) or potential remote code execution (RCE). Fixed in version 3.4.1.14.

Concurrent TDengine Security Advisories: Also disclosed on the same day were CVE-2026-62351 (out‑of‑bounds read DoS), CVE-2026-62350 (UDF RCE), and three other related vulnerabilities.

FortiWeb SQL Injection (CVE-2025-25257) : Affects multiple versions of Fortinet FortiWeb (<=7.6.3, <=7.4.7, <=7.2.10, <7.0.10). Improper neutralisation of special elements in SQL commands allows attackers to perform unauthorised database operations.

- DBA Perspective: As a leading domestic time‑series database, the stack buffer overflow vulnerability (CVSS 8.3) in TDengine reminds DBAs that the security maturity of emerging database components still requires continuous attention. With TDengine widely used in IoT and industrial internet scenarios, DBAs should immediately check versions and upgrade to 3.4.1.14 or higher. As a Web application firewall, the SQL injection vulnerability in FortiWeb means that security products themselves can become attack entry points – DBAs should not relax their defences against application‑layer SQL injection simply because a WAF is deployed.

- CTO Perspective: The disclosure of six vulnerabilities in a single TDengine batch reflects that security testing coverage for time‑series databases, as an emerging category, still needs strengthening. It is recommended that when introducing new database components, vendor security response capability and vulnerability disclosure history be included in the selection evaluation.

## 📚 SQL Little Knowledge Point

This Issue’s Knowledge Point: What is LTAP (Lakehouse Transaction/Analytical Processing)?

LTAP (Lakehouse Transaction/Analytical Processing) is an emerging trend in database development, integrating the open storage capabilities of data lakehouses with the transaction processing capabilities of databases, breaking down the barriers between transaction databases and analytical databases, and eliminating cumbersome ETL data pipeline processes.

Traditional Architecture vs. LTAP Architecture:

| Dimension | Traditional ETL Architecture | LTAP Integrated Architecture |

|-----------|-----------------------------|------------------------------|

| Number of Systems | Transaction DB + Analytics DB (two systems) | Lakehouse integrated (one system) |

| Data Flow | Scheduled ETL sync, hour‑level latency | Real‑time data mirroring, millisecond‑level sync |

| Data Freshness | T+1 or hour‑level | Real‑time |

| Operations Complexity | High (two systems + ETL pipeline) | Low (unified management) |

| AI Agent Support | Stale data, affects real‑time decisions | Real‑time data, supports instant decisions |

GBASE’s LTAP Practice: GBASE achieves LTAP lakehouse integration through the coordination of GBase 8c (transactional) and GBase 8a (analytical) – transaction data is mirrored in real‑time to the analytics side, providing the same fresh data for both online transactions and data analytics, enabling AI agents to make real‑time decisions based on the most up‑to‑date data.

Significance for DBAs: LTAP means DBAs will bid farewell to the tedious maintenance of ETL pipelines, but they will also need to master new skills in real‑time data synchronisation, cross‑system consistency assurance, and mixed‑load tuning.

> HiddenMerit Team Production

> Slogan: 绩优隐于内,金石启新程 | Hidden deep. Merit bold. Forge ahead.

No comments yet