Description
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-06-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle MySQL Shell’s Dump and Load component allows an unauthenticated attacker who can reach the service over the network to compromise the shell. The known issue requires an attacker to leverage human interaction from a person other than the attacker, suggesting that a social‑engineering or credential‑harvesting approach may be needed before the exploit can be triggered. Once compromised, the attacker can read any critical data available through the shell, resulting in a disclosure of confidential information. The weakness aligns with an improper access control flaw (CWE‑284) and directly affects data confidentiality, with no denial of service or code execution impact.

Affected Systems

MySQL Shell from Oracle Corporation, versions 8.4.0 through 8.4.9 and 9.0.0 through 9.7.0. Any installation that has the Dump and Load functionality enabled and is reachable over network protocols is susceptible. Users should verify the installed version against the affected ranges and apply the fix if applicable.

Risk and Exploitability

The CVSS score of 6.5 categorizes this flaw as moderate severity, while an EPSS score of less than 1% indicates a very low current exploitation probability; the vulnerability is also not listed in CISA KEV. Exploitation requires network access and human interaction, reducing the likelihood of automated attacks but still presenting a tangible risk to confidentiality. Timely remediation is recommended to prevent unauthorized data access from occurring.

Generated by OpenCVE AI on June 17, 2026 at 20:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle MySQL Shell to a version later than 8.4.9 or 9.7.0 where the Dump and Load vulnerability has been fixed.
  • If an upgrade cannot be performed immediately, disable the Dump and Load functionality or restrict the shell to trusted administrators only to limit exposure until a patch is applied.
  • Enforce network segmentation or firewall rules so that the MySQL Shell service is not exposed to untrusted networks, thereby removing the required network access for exploitation.

Generated by OpenCVE AI on June 17, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle mysql Shell
CPEs cpe:2.3:a:oracle:mysql_shell:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mysql Shell
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Mysql Shell
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:02:01.715Z

Reserved: 2026-05-18T15:55:10.308Z

Link: CVE-2026-46869

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:00:05Z

Weaknesses

No weakness.