Junglewise Threat Intelligence

CVE-2026-46869: Oracle MySQL Shell CSRF in Dump and Load component

CVE-2026-46869 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle MySQL Shell's Dump and Load component, which is used for migrating and backing up database data. An attacker could trick a user into performing an action that allows the attacker to gain unauthorized access to sensitive database information. This could lead to the exposure of critical business data or a complete breach of all data accessible through the shell.

Technical details

A vulnerability classified as Cross-Site Request Forgery (CSRF) exists in the 'Dump and Load' component of Oracle MySQL Shell. The flaw allows an unauthenticated remote attacker to compromise the MySQL Shell environment if they can successfully induce a legitimate user to perform a specific action (User Interaction). While the attack is easily exploitable, it is limited to confidentiality impacts, potentially allowing the attacker to gain unauthorized access to all data accessible by the shell. Affected versions include 8.4.0 through 8.4.9 and 9.0.0 through 9.7.0.

Affected products

  • Oracle MySQL Shell 8.4.0 - 8.4.9, 9.0.0 - 9.7.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References