CVE-2026-46871
Awaiting Analysis Awaiting Analysis - Queue
MySQL Shell for VS Code Unauthorized Data Access

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
oracle mysql_shell to 2026.2.0+9.6.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the MySQL Shell product of Oracle MySQL, specifically in the Shell for VS Code component. It affects the supported version 2026.2.0+9.6.1 and allows a low privileged attacker with network access via multiple protocols to exploit it easily.

Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible through MySQL Shell.

Impact Analysis

The vulnerability can allow an attacker with low privileges and network access to gain unauthorized access to critical data within MySQL Shell.

This means sensitive or important data could be exposed or compromised without proper authorization.

Compliance Impact

This vulnerability allows a low privileged attacker with network access to gain unauthorized access to critical data or all data accessible by MySQL Shell. Such unauthorized access to sensitive or critical data can potentially lead to non-compliance with data protection regulations and standards such as GDPR and HIPAA, which require strict controls over access to personal and sensitive information.

Therefore, organizations using the affected MySQL Shell version may face increased risk of data breaches that could violate these regulations, resulting in legal and financial consequences.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46871. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart