CVE-2026-46860
Critical · CVSS 9.8MySQL Router — Improper Access Control (CWE-284) leading to unauthenticated remote takeover via HTTP
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-284
Description
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in takeover of MySQL Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Search profile — drives PoC discovery
Symbols MySQL RouterRouter: GeneralHTTPunauthenticatednetwork accesstakeovermysqlrouterREST APIbootstraprouter configuration
Keywords CVE-2026-46860MySQL Router RCEMySQL Router unauthenticatedMySQL Router HTTP exploitMySQL Router 9.0 vulnerabilityMySQL Router takeoverOracle MySQL Router PoCCVE-2026-46860 exploitMySQL Router access control bypassCWE-284 MySQL Router
Versions: 9.0.0 - 9.7.0
References
Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z