MySQL Shell Vulnerability in Oracle MySQL Affects Multiple Versions
CVE-2026-34319

5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-34319?

A vulnerability exists in the MySQL Shell component of Oracle MySQL, allowing low-privileged attackers with access to an affected instance to exploit the system through human interaction. This can result in unauthorized access to cause significant disruptions, such as causing the MySQL Shell to hang or crash repeatedly. The affected versions are 8.0.0 to 8.0.45, 8.4.0 to 8.4.8, and 9.0.0 to 9.6.0. Such issues emphasize the importance of maintaining stringent access controls and being vigilant about user permissions.

Affected Version(s)

MySQL Shell 8.0.0 <= 8.0.45

MySQL Shell 8.4.0 <= 8.4.8

MySQL Shell 9.0.0 <= 9.6.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.