Executive brief
A vulnerability exists in the MySQL Shell extension for Visual Studio Code, a tool used by developers and database administrators to manage MySQL databases. An attacker with basic user credentials can exploit this flaw over a network to gain unauthorized access to sensitive database information. This could lead to the exposure of critical business data or a complete breach of all data accessible through the MySQL Shell interface.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the MySQL Shell for VS Code component. It is easily exploitable by a low-privileged attacker with network access via multiple protocols. The flaw does not require user interaction and has a low attack complexity. Successful exploitation allows the attacker to bypass intended security restrictions to achieve high confidentiality impacts, potentially accessing all data the MySQL Shell is authorized to view. The affected version is 2026.2.0+9.6.1.
Affected products
- Oracle MySQL Shell (Shell for VS Code) 2026.2.0+9.6.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published