MySQL Shell Vulnerability in Oracle MySQL
CVE-2026-34318

5.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-34318?

A vulnerability has been identified in Oracle MySQL's Shell product, specifically affecting versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0. This vulnerability allows a well-privileged attacker with network access using multiple protocols to exploit MySQL Shell. The implications of a successful attack include unauthorized access to sensitive data, potentially leading to a broader compromise across additional systems accessible through MySQL Shell. Organizations utilizing these affected versions should implement the recommended updates to mitigate the risk associated with this vulnerability.

Affected Version(s)

MySQL Shell 8.0.0 <= 8.0.45

MySQL Shell 8.4.0 <= 8.4.8

MySQL Shell 9.0.0 <= 9.6.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.