HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46870Published Modified CNA oracle

CVE-2026-46870: Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code)

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.5
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a network-exploitable privilege escalation and full-takeover vulnerability in the Shell for VS Code component of Oracle MySQL Shell version 2026.2.0+9.6.1. A low-privileged attacker with network access can exploit the flaw over multiple protocols, though reliable exploitation requires overcoming elevated complexity conditions. Successful exploitation results in a complete takeover of MySQL Shell, with high impact to confidentiality, integrity, and availability, and the scope change means adjacent products or containers can also be affected. No fix version has been published yet; HarborGuard tracks this advisory and will make a patched-image rebuild available as soon as Oracle ships a fix.

HarborGuard Coverage

Detection

Detection of CVE-2026-46870 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including internally built images that bundle MySQL Shell or the VS Code extension layer.

Available
Triage

Triage is available with the full CVSS 3.1 score of 8.5 (HIGH) surfaced alongside per-environment compliance policy weighting, so each customer's policy can escalate or prioritize accordingly; findings are routed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

Because no fix version has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle publishes a corrected release. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be triggered automatically at that point.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the MySQL Shell service over the network via one or more supported protocols; no local or physical access is assumed.

  • AuthenticationRequired

    A low-privilege account on the target system or service is sufficient; anonymous or unauthenticated access alone does not satisfy this condition.

  • Victim interactionNot required

    No user interaction is needed; the attacker can execute the attack entirely without involving another person.

  • Attack complexityDetail

    Exploitation is rated High complexity, meaning the attacker must meet specific environmental conditions, such as race conditions or particular configuration states, before the attack reliably succeeds.

Blast Radius

  • A successful attacker gains full read access to all data accessible by MySQL Shell, including database credentials, query results, and stored connection profiles.
  • The attacker can modify or delete database contents, configuration files, and shell session state, corrupting persisted data.
  • The attacker can crash or hang the MySQL Shell process, disrupting developer and pipeline workflows that depend on it.
  • Because the CVSS scope is changed, exploitation can pivot to affect other products or services running in the same environment, such as connected database servers or VS Code extension host processes.

How HarborGuard Handles This

Available on HarborGuard: continuous monitoring of the Oracle advisory for CVE-2026-46870 is active across all customer environments that include images containing MySQL Shell 2026.2.0+9.6.1. Because no upstream fix exists today, HarborGuard re-evaluates the advisory on every ingest cycle. The moment Oracle publishes a patched release, a rebuilt image at that fix version becomes available, and for customers who have opted into auto-remediation, the pipeline will trigger a rebuild, run regression tests, and open a PR against affected workloads automatically. In the interim, recommended compensating controls include applying network policy to restrict which services and protocols can reach MySQL Shell instances, enforcing egress filtering to limit lateral movement in the event of a scope-change exploit, and auditing which low-privilege accounts have network access to the Shell for VS Code endpoint.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / MySQL Shell
    2026.2.0+9.6.1
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
References