CVE-2026-46869
Description
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Summary dbcve.org
Vulnerability in MySQL Shell's Dump and Load component allows unauthenticated remote attackers to potentially access sensitive data. The attack requires human interaction (tricking a user), and network access via multiple protocols. Successful exploitation grants unauthorized read access to data that MySQL Shell can access.
Mitigation
Upgrade MySQL Shell to a patched version beyond 8.4.9 or 9.7.0. Additionally, restrict network access to MySQL Shell and educate users about suspicious dump/load operations from untrusted sources.