CVE-2026-46860: Oracle MySQL Router

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in takeover of MySQL Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected products

  • Oracle MySQL Router: from 9.0.0, up to and including 9.7.0

Published 2026-06-17. Last modified 2026-06-18.