MEDIUM

CVE-2026-46869

Oracle Mysql Shell 2026-06-17 CVSS v3.1
CVSS
6.5

Description

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).

Summary dbcve.org

Vulnerability in MySQL Shell's Dump and Load component allows unauthenticated remote attackers to potentially access sensitive data. The attack requires human interaction (tricking a user), and network access via multiple protocols. Successful exploitation grants unauthorized read access to data that MySQL Shell can access.

Mitigation

Upgrade MySQL Shell to a patched version beyond 8.4.9 or 9.7.0. Additionally, restrict network access to MySQL Shell and educate users about suspicious dump/load operations from untrusted sources.

Weakness (CWE)

CWE-352 Cross-Site Request Forgery (CSRF)

EPSS Score

0.18%
Probability of exploitation in next 30 days
7.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE