Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-46870

Опубликовано: 17 июн. 2026
Источник: nvd
CVSS3: 8.5
EPSS Низкий

Описание

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:oracle:mysql_shell:2026.2.0:*:*:*:*:visual_studio_code:*:*

EPSS

Процентиль: 23%
0.00311
Низкий

8.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.5
github
около 1 месяца назад

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.5
fstec
около 2 месяцев назад

Уязвимость компонента Shell for VS Code клиента командной строки и редактора кода Oracle MySQL Shell, позволяющая нарушителю получить полный контроль над системой

EPSS

Процентиль: 23%
0.00311
Низкий

8.5 High

CVSS3

Дефекты

CWE-284