Junglewise Threat Intelligence

CVE-2026-46850: Oracle MySQL Shell code injection in Shell for VS Code

CVE-2026-46850 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle MySQL Shell for VS Code. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the MySQL Shell for VS Code, a tool used by developers and database administrators to manage MySQL databases within the Visual Studio Code environment. An attacker with low-level access can remotely take full control of the tool, potentially leading to the theft of sensitive database credentials or unauthorized access to connected database systems. This flaw is particularly serious because it can be used as a stepping stone to compromise other parts of the corporate network or development environment.

Technical details

A vulnerability classified as Improper Control of Generation of Code (CWE-94) exists in the 'Shell for VS Code' component of Oracle MySQL Shell. The flaw allows a low-privileged attacker with network access via HTTP to execute arbitrary code or commands, leading to a complete takeover of the MySQL Shell environment. The vulnerability is notable for its 'Scope Change' (S:C) designation, indicating that an exploit can impact resources beyond the immediate security scope of the MySQL Shell itself. The issue is easily exploitable and affects version 2026.2.0+9.6.1. Users are advised to consult the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle MySQL Shell for VS Code 2026.2.0+9.6.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats