CVE-2026-46862
Awaiting Analysis Awaiting Analysis - Queue
Denial of Service in MySQL Router

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
oracle mysql_router From 8.4.0 (inc) to 8.4.9 (inc)
oracle mysql_router From 9.0.0 (inc) to 9.7.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability in MySQL Router allows an unauthenticated attacker to cause a denial of service (DoS) by crashing the service, impacting availability.

Since the vulnerability affects availability but does not impact confidentiality or integrity, its direct effect on compliance with standards like GDPR or HIPAAβ€”which emphasize data protection and privacyβ€”is limited.

However, availability is a component of many compliance frameworks, so repeated or prolonged denial of service could potentially affect compliance related to system availability requirements.

Executive Summary

This vulnerability exists in the MySQL Router product of Oracle MySQL, specifically affecting versions 8.4.0 through 8.4.9 and 9.0.0 through 9.7.0. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via TLS to compromise the MySQL Router.

The attacker can cause the MySQL Router to hang or crash repeatedly, resulting in a complete denial of service (DoS).

Impact Analysis

The primary impact of this vulnerability is on availability. An attacker can cause the MySQL Router to hang or crash frequently, leading to a complete denial of service.

This means that legitimate users may be unable to access services relying on the MySQL Router, potentially disrupting business operations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart