No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspujun2026.html |
|
Thu, 18 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Exploitable Code Injection Allowing Remote Takeover of MySQL Shell |
Thu, 18 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution in Oracle MySQL Shell via HTTP | |
| Weaknesses | CWE-284 |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution in Oracle MySQL Shell via HTTP | |
| Weaknesses | CWE-284 CWE-94 |
|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle mysql Shell |
|
| CPEs | cpe:2.3:a:oracle:mysql_shell:2026.2.0\+9.6.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle mysql Shell |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-06-18T03:56:47.248Z
Reserved: 2026-05-18T15:55:10.306Z
Link: CVE-2026-46850
Updated: 2026-06-17T14:06:50.506Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T23:30:16Z