Executive brief
A vulnerability exists in the MySQL Shell extension for Visual Studio Code, a tool used by developers and database administrators to manage MySQL databases. A remote attacker with low-level access could exploit this flaw to take full control of the MySQL Shell environment. Because this tool integrates with other development systems, a successful attack could potentially compromise additional software or data beyond the database shell itself.
Technical details
This vulnerability is classified as Improper Access Control (CWE-284) within the 'Shell for VS Code' component of Oracle MySQL Shell. It is reachable via multiple protocols over the network, though exploitation is considered difficult (High Attack Complexity) and requires at least low-privileged user credentials. The flaw is notable for a 'Scope Change' (S:C), meaning a successful exploit can impact resources beyond the immediate security scope of the MySQL Shell. Successful exploitation results in a complete loss of confidentiality, integrity, and availability for the affected component. Version 2026.2.0+9.6.1 is explicitly listed as affected.
Affected products
- Oracle MySQL Shell for VS Code 2026.2.0+9.6.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory