Junglewise Threat Intelligence

CVE-2026-46860: Oracle MySQL Router unauthenticated compromise in Router General

CVE-2026-46860 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle MySQL Router. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle MySQL Router, a tool used to manage traffic and high availability between applications and MySQL databases. An unauthenticated attacker can exploit this flaw over the network to gain full control of the Router component. This could lead to a total loss of service availability, unauthorized access to sensitive database traffic, and potential manipulation of data passing through the router.

Technical details

A vulnerability exists in the 'Router: General' component of Oracle MySQL Router versions 9.0.0 through 9.7.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the MySQL Router instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8, indicating high severity due to the lack of required privileges or user interaction. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle MySQL Router 9.0.0 - 9.7.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats